Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-0782

Опубликовано: 05 авг. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5
CVSS3: 5.4

Описание

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

РелизСтатусПримечание
devel

not-affected

code disabled
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code disabled]]
precise

not-affected

code disabled
trusty

not-affected

code disabled
trusty/esm

DNE

trusty was not-affected [code disabled]
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

code disabled

Показывать по

EPSS

Процентиль: 78%
0.01162
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
redhat
почти 10 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

CVSS3: 5.4
nvd
больше 9 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

CVSS3: 5.4
debian
больше 9 лет назад

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5 ...

CVSS3: 5.4
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

EPSS

Процентиль: 78%
0.01162
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3