Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0782

Опубликовано: 10 мар. 2016
Источник: redhat
CVSS3: 4.2
CVSS2: 3.5
EPSS Низкий

Описание

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

It was found that Apache Active MQ administration web console did not validate input correctly when creating a queue. An authenticated attacker could exploit this flaw via cross-site scripting and use it to access sensitive information or further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6activemqAffected
Red Hat JBoss Fuse 6activemqNot affected
Red Hat JBoss Fuse Service Works 6activemqWill not fix
Red Hat OpenShift Enterprise 2activemqAffected
Red Hat JBoss A-MQ 6.2FixedRHSA-2016:142413.07.2016
Red Hat JBoss Fuse 6.2FixedRHSA-2016:142413.07.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1317516activemq: Cross-site scripting vulnerabilities in web console

EPSS

Процентиль: 93%
0.06068
Низкий

4.2 Medium

CVSS3

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 10 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

CVSS3: 5.4
nvd
около 10 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

CVSS3: 5.4
debian
около 10 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5 ...

CVSS3: 5.4
github
больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

EPSS

Процентиль: 93%
0.06068
Низкий

4.2 Medium

CVSS3

3.5 Low

CVSS2