PT-2026-65496 · Apache · Apache Tomcat+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Axis2/Java versions prior to 2.0.1
Description
An issue exists in the Tribes-based clustering component when running on Apache Tomcat. When Tribes clustering is enabled, an unauthenticated remote attacker with network access to the clustering port can execute arbitrary code. This is achieved by sending a crafted serialized Java object to the cluster channel, which is then deserialized in the
messageReceived() function of org.apache.axis2.clustering.tribes.Axis2ChannelListener. Deserialization is the process of converting a stream of bytes back into an object in memory.Recommendations
Upgrade to version 2.0.1.
As a temporary workaround, ensure that Tribes clustering remains disabled.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Axis2
Apache Tomcat