Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7559

Опубликовано: 19 апр. 2017
Источник: redhat
CVSS3: 2.7
CVSS2: 2.6

Описание

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

It was found that the Apache ActiveMQ client exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6.2.1amq-clientAffected
Red Hat JBoss A-MQ 6.3FixedRHSA-2017:086803.04.2017
Red Hat JBoss Fuse 6.3FixedRHSA-2017:086803.04.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=1293972ActiveMQ: DoS in client via shutdown command

2.7 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 2.7
ubuntu
больше 6 лет назад

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

CVSS3: 2.7
nvd
больше 6 лет назад

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

CVSS3: 2.7
debian
больше 6 лет назад

It was found that the Apache ActiveMQ client before 5.14.5 exposed a r ...

CVSS3: 4.9
github
больше 6 лет назад

Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ

2.7 Low

CVSS3

2.6 Low

CVSS2