ObjectMessage: unsafe deserialization
Published Jan 8, 2016
9.8
CRITICALCVSS 3.0
EPSS 38.19%
Description
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
Affected products
No data.
Configuration 2
- 5.0.0
- 5.1.0
- 5.2.0
- 5.3.0
- 5.3.1
- 5.3.2
- 5.4.0
- 5.4.1
- 5.4.3
- 5.5.0
- 5.5.1
- 5.6.0
- 5.7.0
- 5.8.0
- 5.9.0
- 5.9.1
- 5.10.0
- 5.10.1
- 5.10.2
- 5.11.0
- 5.11.1
- 5.11.2
- 5.12.0
- 5.12.1
Configuration 3
- 22
- 23
No data.
Red Hat JBoss A-MQ 6.3
n/a
Fixed · RHSA-2016:2036
Red Hat JBoss Fuse 6.3
n/a
Fixed · RHSA-2016:2035
Red Hat OpenShift Enterprise 2.2
activemq-0:5.9.0-6.redhat.611454.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
jenkins-0:1.625.3-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-enterprise-upgrade-0:2.2.9-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-broker-util-0:1.37.5.3-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-cron-0:1.25.2.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-haproxy-0:1.31.5.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-mysql-0:1.31.2.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-php-0:1.35.3.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-cartridge-python-0:1.34.2.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-msg-node-mcollective-0:1.30.2.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-node-proxy-0:1.26.2.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
openshift-origin-node-util-0:1.38.6.2-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
php-0:5.3.3-46.el6_7.1
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
rhc-0:1.38.6.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-common-0:1.29.5.2-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-console-0:1.35.5.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-controller-0:1.38.5.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-frontend-apache-vhost-0:0.13.2.1-1.el6op
Fixed · RHSA-2016:0489
Red Hat OpenShift Enterprise 2.2
rubygem-openshift-origin-node-0:1.38.5.3-1.el6op
Fixed · RHSA-2016:0489
Red Hat JBoss A-MQ 6
activemq
Affected
Red Hat JBoss Enterprise Application Platform 6
hornetq
Will not fix
Red Hat JBoss Enterprise Application Platform 7
artemis
Will not fix
Red Hat JBoss Fuse 6
activemq
Affected
Red Hat JBoss Fuse Service Works 6
activemq
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss A-MQ 6.3 | n/a | Fixed | RHSA-2016:2036 |
| Red Hat JBoss Fuse 6.3 | n/a | Fixed | RHSA-2016:2035 |
| Red Hat OpenShift Enterprise 2.2 | activemq-0:5.9.0-6.redhat.611454.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | jenkins-0:1.625.3-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-enterprise-upgrade-0:2.2.9-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-broker-util-0:1.37.5.3-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-cron-0:1.25.2.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-haproxy-0:1.31.5.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-mysql-0:1.31.2.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-php-0:1.35.3.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-cartridge-python-0:1.34.2.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-msg-node-mcollective-0:1.30.2.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-node-proxy-0:1.26.2.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | openshift-origin-node-util-0:1.38.6.2-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | php-0:5.3.3-46.el6_7.1 | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | rhc-0:1.38.6.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-common-0:1.29.5.2-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-console-0:1.35.5.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-controller-0:1.38.5.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-frontend-apache-vhost-0:0.13.2.1-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat OpenShift Enterprise 2.2 | rubygem-openshift-origin-node-0:1.38.5.3-1.el6op | Fixed | RHSA-2016:0489 |
| Red Hat JBoss A-MQ 6 | activemq | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | hornetq | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | artemis | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | activemq | Affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | activemq | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A malicious message producer needs to authenticate to EAP in order to send messages. Also, the use of JMS ObjectMessage needs to be chosen by the developer of the application. Therefore this issue is rated as moderate.
Red Hat mitigation
If you do deploy a JMS publisher, and subscriber, and don't trust the messages sent to you by your clients, you could mitigate this issue by installing a Java agent which restricts the classes which can be deserialized. This is an article with the recommended approach: https://access.redhat.com/solutions/2190911 You could also mitigate this issue using the features of the Java Virtual Machine added in JEP 290: http://openjdk.java.net/jeps/290
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (29 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 38.19% (0.38191) | 98.52th | v5 (v2026.06.15) |
| Sep 22, 2026 | 38.19% (0.38191) | 98.50th | v5 (v2026.06.15) |
| Sep 21, 2026 | 34.53% (0.34528) | 98.39th | v5 (v2026.06.15) |
| Sep 6, 2026 | 38.19% (0.38191) | 98.46th | v5 (v2026.06.15) |
| Sep 5, 2026 | 34.53% (0.34528) | 98.35th | v5 (v2026.06.15) |
| Aug 30, 2026 | 38.19% (0.38191) | 98.45th | v5 (v2026.06.15) |
| Aug 28, 2026 | 34.53% (0.34528) | 98.34th | v5 (v2026.06.15) |
| Aug 24, 2026 | 38.19% (0.38191) | 98.45th | v5 (v2026.06.15) |
| Aug 23, 2026 | 34.53% (0.34528) | 98.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 37.94% (0.37936) | 98.36th | v5 (v2026.06.15) |
| Jun 10, 2026 | 75.51% (0.75508) | 98.91th | v4 (v2025.03.14) |
| Feb 11, 2026 | 80.11% (0.80110) | 99.08th | v4 (v2025.03.14) |
| Dec 28, 2025 | 77.15% (0.77148) | 98.92th | v4 (v2025.03.14) |
| Dec 27, 2025 | 80.39% (0.80393) | 99.09th | v4 (v2025.03.14) |
| Oct 28, 2025 | 77.15% (0.77148) | 98.91th | v4 (v2025.03.14) |
| Oct 27, 2025 | 80.39% (0.80393) | 99.08th | v4 (v2025.03.14) |
| Oct 1, 2025 | 77.15% (0.77148) | 98.94th | v4 (v2025.03.14) |
| Jul 30, 2025 | 80.39% (0.80393) | 99.07th | v4 (v2025.03.14) |
| Jul 3, 2025 | 77.15% (0.77148) | 98.91th | v4 (v2025.03.14) |
| Mar 30, 2025 | 84.93% (0.84934) | 99.29th | v4 (v2025.03.14) |
| Mar 29, 2025 | 87.86% (0.87856) | 99.36th | v4 (v2025.03.14) |
| Mar 28, 2025 | 84.93% (0.84934) | 99.29th | v4 (v2025.03.14) |
| Mar 27, 2025 | 87.86% (0.87856) | 99.43th | v4 (v2025.03.14) |
| Mar 17, 2025 | 84.93% (0.84934) | 99.30th | v4 (v2025.03.14) |
| Feb 1, 2025 | 2.59% (0.02594) | 90.13th | v3 (v2023.03.01) |
| Dec 12, 2024 | 3.62% (0.03618) | 92.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.86% (0.03859) | 90.52th | v3 (v2023.03.01) |
| Mar 6, 2023 | 67.67% (0.67675) | 99.10th | v2 (v2022.01.01) |
| Feb 4, 2022 | 67.67% (0.67675) | 98.91th | v2 (v2022.01.01) |
References (23)
- http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174371.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174537.html vendor-advisoryx_refsource_FEDORA
- http://rhn.redhat.com/errata/RHSA-2016-0489.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-2035.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-2036.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2016/dsa-3524 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2015/12/08/6 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2015-5254 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1291292 Issue Tracking
- https://github.com/advisories/GHSA-q9hr-3pg4-3jp4 Advisory
- https://github.com/apache/activemq/commit/6f03921b31d9fefeddb0f4fa63150ed1f94a14b
- https://github.com/apache/activemq/commit/73a0caf758f9e4916783a205c7e422b4db27905
- https://github.com/apache/activemq/commit/7eb9b218b2705cf9273e30ee2da026e43b6dd4e
- https://github.com/apache/activemq/commit/e7a4b53f799685e337972dd36ba0253c04bcc01
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 x_refsource_CONFIRM
- https://issues.apache.org/jira/browse/AMQ-6013 x_refsource_CONFIRMVendor Advisory
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2015-5254
- https://www.cve.org/CVERecord?id=CVE-2015-5254
Change history (0)
No recorded changes yet.