Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0734

Опубликовано: 10 мар. 2016
Источник: redhat
CVSS3: 3.1
CVSS2: 4.3
EPSS Низкий

Описание

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

It was reported that the web based administration console does not set the X-Frame-Options header in HTTP responses. This allows the console to be embedded in a frame or iframe which could then be used to cause a user to perform an unintended action in the console.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6activemqAffected
Red Hat JBoss Fuse 6activemqNot affected
Red Hat JBoss Fuse Service Works 6activemqNot affected
Red Hat OpenShift Enterprise 2activemqAffected
Red Hat JBoss A-MQ 6.2FixedRHSA-2016:142413.07.2016
Red Hat JBoss Fuse 6.2FixedRHSA-2016:142413.07.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1317520activemq: Clickjacking in Web Console

EPSS

Процентиль: 86%
0.02975
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 10 лет назад

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

CVSS3: 6.1
nvd
почти 10 лет назад

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

CVSS3: 6.1
debian
почти 10 лет назад

The web-based administration console in Apache ActiveMQ 5.x before 5.1 ...

CVSS3: 6.1
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

fstec
почти 10 лет назад

Уязвимость программной платформы Apache ActiveMQ, позволяющая нарушителю разместить на странице вредоносные элементы и навязать пользователю их активацию

EPSS

Процентиль: 86%
0.02975
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS2