Описание
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
Отчет
Fuse ESB Enterprise 7.1.0, Fuse MQ Enterprise 7.1.1, JBoss Fuse 6.0.0 and JBoss A-MQ 6.0.0 all contain the Apache ActiveMQ web console, but it is not deployed by default. The documentation for deploying the web console covers the configuration needed to ensure authentication is enabled, therefore these products are not affected by this flaw. In a future update to these products, the web console will be configured so that authentication is automatically enabled if the web console is deployed, eliminating the need to manually configure it. A future update may address this flaw in Fuse Message Broker 5.5.1.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | activemq | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | amq | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-6.0 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-esb-7.1 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mb-5.5.1 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mc-7.1.0 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mq-7.1 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-others | Will not fix | ||
| Red Hat JBoss Enterprise Web Server 1 | others | Not affected | ||
| Red Hat JBoss SOA Platform 4.3 | activemq | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS2
Связанные уязвимости
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
The web console in Apache ActiveMQ before 5.8.0 does not require authe ...
EPSS
7.5 High
CVSS2