Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5181

Опубликовано: 06 окт. 2015
Источник: redhat
CVSS2: 3.5

Описание

The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.

It was found that the JBoss A-MQ console would accept a string containing JavaScript as the name of a new message queue. Execution of the UI would subsequently execute the script. An attacker could use this flaw to access sensitive information or perform other attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1amq-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss A-MQ 6.2FixedRHSA-2015:255707.12.2015
Red Hat JBoss Fuse 6.2FixedRHSA-2015:255607.12.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1248804Console: script injection into queue name

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 5.4
nvd
больше 8 лет назад

The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.

CVSS3: 5.4
github
больше 3 лет назад

The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.

3.5 Low

CVSS2