Intrusion Prevention

Apache.ActiveMQ.ObjectMessage.Code.Execution

Description

This indicates an attack attempt against a Code Execution vulnerability in Apache ActiveMQ.
The vulnerability is caused by an error when the broker de-serializes a crafted Java Message Service (JMS) ObjectMessage object. A remote attacker may be able to exploit this to execute arbitrary code on the affected systems.

Affected Products

Apache ActiveMQ 5.x before 5.13.0

Impact

System Compromise: Remote attacker can gain control of vulnerable systems.

Recommended Actions

Refer to the vendor's website for patch or update.
http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt

CVE References

CVE-2015-5254