Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-3094

Опубликовано: 01 июн. 2016
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:qpid_broker-j:*:*:*:*:*:*:*:*
Версия до 6.0.2 (включая)

EPSS

Процентиль: 76%
0.00989
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

redhat
больше 9 лет назад

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

CVSS3: 5.9
debian
больше 9 лет назад

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker ...

CVSS3: 5.9
github
больше 7 лет назад

Improper Input Validation in org.apache.qpid:qpid-broker

EPSS

Процентиль: 76%
0.00989
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20