Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2016-07-13T15:00:00

Updated: 2018-10-09T18:57:01

Reserved: 2016-05-24T00:00:00


Link: CVE-2016-4974

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2016-07-13T15:59:04.857

Modified: 2018-10-09T20:00:28.163


Link: CVE-2016-4974

JSON object: View

cve-icon Redhat Information

No data.

CWE