CVE-2025-27533
- EPSS 0.35%
- Published 07.05.2025 09:15:18
- Last modified 18.07.2025 14:50:06
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a ...
CVE-2024-32114
- EPSS 2.05%
- Published 02.05.2024 09:15:06
- Last modified 11.02.2025 16:31:00
In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, an...
CVE-2022-41678
- EPSS 71.04%
- Published 28.11.2023 16:15:06
- Last modified 21.11.2024 07:23:37
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandle...
CVE-2023-46604
- EPSS 94.44%
- Published 27.10.2023 15:15:14
- Last modified 06.03.2025 19:48:51
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating seria...
CVE-2021-21351
- EPSS 90.49%
- Published 23.03.2021 00:15:13
- Last modified 23.05.2025 17:34:20
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed inpu...
CVE-2021-21350
- EPSS 7.11%
- Published 23.03.2021 00:15:13
- Last modified 23.05.2025 17:43:08
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is a...
CVE-2021-21349
- EPSS 6.75%
- Published 23.03.2021 00:15:13
- Last modified 23.05.2025 17:42:48
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipul...
CVE-2021-21348
- EPSS 0.2%
- Published 23.03.2021 00:15:13
- Last modified 23.05.2025 17:42:08
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is aff...
CVE-2021-21347
- EPSS 2.63%
- Published 23.03.2021 00:15:13
- Last modified 23.05.2025 17:41:49
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processe...
CVE-2021-21344
- EPSS 28.06%
- Published 23.03.2021 00:15:12
- Last modified 23.05.2025 17:40:53
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processe...