It is hard to determine based on that message and https://issues.apache.org/jira/browse/COLLECTIONS-580. Based on my searching so far, it looks like that feature of collections is not used in ActiveMQ.
Specifically, I searched on InvokerTransformer and did not find any occurrence in the code. It would help to have specific details of how commons collection is vulnerable. ActiveMQ does use commons collection. Note that I do know for sure that the openwire implementation uses its own serialization methods, so it's highly unlikely that the openwire protocol is suceptible. -- View this message in context: http://activemq.2283324.n4.nabble.com/Java-December-vulnerability-tp4704610p4704618.html Sent from the ActiveMQ - User mailing list archive at Nabble.com.