top of page
perceptive_background_267k.jpg

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component

 in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache …

Published:

27 July 2026 at 22:00:00

Alert date:

28 July 2026 at 17:04:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A critical deserialization vulnerability (CWE-502) exists in the Tribes-based clustering component of Apache Axis2/Java through version 2.0.0 when deployed on Apache Tomcat. The flaw allows an unauthenticated remote attacker with network access to the clustering port to execute arbitrary code by delivering a crafted serialized Java object to the cluster channel. The vulnerable code path is in org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. The vulnerability is only exploitable when Tribes clustering is explicitly enabled, which is off by default. Apache has addressed the issue in version 2.0.1 by completely removing the clustering feature. Users are strongly advised to upgrade to version 2.0.1 immediately. The fix is confirmed via a commit to the official Apache Axis2 Java core GitHub repository.

Technical details

Mitigation steps:

Affected products:

Apache Axis2/Java 2.0.0 and earlier
Apache Tomcat

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page