← back
CVE-2015-5254

CVE-2015-5254

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 38%
exploitation probability
38%top 2% of all CVEs
observed exploitation
nono source reports it
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
Affected products
n/a · n/a