RSS   Vulnerabilities for 'Activemq'   RSS

2018-02-13
 
CVE-2017-15709

CWE-200
 

 
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

 
2018-01-10
 
CVE-2016-6810

CWE-79
 

 
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.

 
2017-10-27
 
CVE-2014-3600

CWE-611
 

 
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

 
2017-09-25
 
CVE-2015-5184

 

 
The Hawtio console in A-MQ allows remote attackers to obtain sensitive information and perform other unspecified impact.

 
 
CVE-2015-5183

 

 
The Hawtio console in A-MQ does not set HTTPOnly or Secure attributes on cookies.

 
 
CVE-2015-5182

 

 
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.

 
2016-08-05
 
CVE-2016-0782

 

 
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

 
2016-06-01
 
CVE-2016-3088

CWE-20
 

 
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

 
2016-04-07
 
CVE-2016-0734

 

 
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

 
2016-01-08
 
CVE-2015-5254

CWE-20
 

 
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

 


Copyright 2018, cxsecurity.com

 

Back to Top