RSS   Vulnerabilities for 'Activemq'   RSS

2018-01-10
 
CVE-2016-6810

CWE-79
 

 
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.

 
2017-10-27
 
CVE-2014-3600

CWE-611
 

 
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

 
2017-09-25
 
CVE-2015-5184

 

 
The Hawtio console in A-MQ allows remote attackers to obtain sensitive information and perform other unspecified impact.

 
 
CVE-2015-5183

 

 
The Hawtio console in A-MQ does not set HTTPOnly or Secure attributes on cookies.

 
 
CVE-2015-5182

 

 
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.

 
2016-08-05
 
CVE-2016-0782

 

 
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

 
2016-06-01
 
CVE-2016-3088

CWE-20
 

 
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

 
2016-04-07
 
CVE-2016-0734

 

 
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

 
2016-01-08
 
CVE-2015-5254

CWE-20
 

 
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

 
2015-08-24
 
CVE-2015-6524

 

 
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.

 


Copyright 2018, cxsecurity.com

 

Back to Top