Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0782

Опубликовано: 10 мар. 2016
Источник: redhat
CVSS3: 4.2
CVSS2: 3.5

Описание

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

It was found that Apache Active MQ administration web console did not validate input correctly when creating a queue. An authenticated attacker could exploit this flaw via cross-site scripting and use it to access sensitive information or further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6activemqAffected
Red Hat JBoss Fuse 6activemqNot affected
Red Hat JBoss Fuse Service Works 6.0.0activemqWill not fix
Red Hat JBoss Fuse Service Works 6.2.1activemqNot affected
Red Hat OpenShift Enterprise 2activemqAffected
Red Hat JBoss A-MQ 6.2FixedRHSA-2016:142413.07.2016
Red Hat JBoss Fuse 6.2FixedRHSA-2016:142413.07.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1317516activemq: Cross-site scripting vulnerabilities in web console

4.2 Medium

CVSS3

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 9 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

CVSS3: 5.4
nvd
больше 9 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

CVSS3: 5.4
debian
больше 9 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5 ...

CVSS3: 5.4
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

4.2 Medium

CVSS3

3.5 Low

CVSS2