Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-4974

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.026
EPSS Ranking 84.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.0
Products affected by CVE-2016-4974


Contact Us

Shodan ® - All rights reserved