Page 3 of 35 results (0.007 seconds)

CVSS: 7.5EPSS: 88%CPEs: 23EXPL: 4

19 Aug 2015 — Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors. Vulnerabilidad de salto de directorio en la funcionalidad del servidor de ficheros upload/download para mensajes blob en Apache ActiveMQ 5.x en versiones anteriores a 5.11.2 para Windows, permite a atacantes remotos crear archivos JSP en directorios arbitrarios a travé... • https://packetstorm.news/files/id/156643 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 20%CPEs: 6EXPL: 0

11 Aug 2015 — The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command. Vulnerabilidad en la función processControlCommand en broker/TransportConnection.java en Apache ActiveMQ en versiones anteriores a 5.11.0, permite a atacantes remotos causar una denegación de servicio (apagado) a través de un comando de apagado. It was found that the Apache ActiveMQ broker exposed a remote shutdown comm... • http://activemq.2283324.n4.nabble.com/About-CVE-2014-3576-tp4699628.html • CWE-264: Permissions, Privileges, and Access Controls CWE-306: Missing Authentication for Critical Function •

CVSS: 4.3EPSS: 5%CPEs: 18EXPL: 1

12 Feb 2015 — Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en la consola de administración basada en web en Apache ActiveMQ 5.x anterior a 5.10.1 permiten a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de vectores no especificados. • https://github.com/tafamace/CVE-2014-8110 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 18EXPL: 0

05 Feb 2015 — XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages. Una vulnerabilidad de XML External Entity (XXE) en Apache ActiveMQ, en versiones 5.x anteriores a la 5,10,1 permite que consumidores remotos provoquen impactos no especificados mediante vectores que implican un selector basado en XPath al eliminar de la cola los mensajes XML. It was discovered that Apache Ac... • http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txt • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 7.5EPSS: 0%CPEs: 18EXPL: 0

05 Feb 2015 — The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames. La implementación de LDAPLoginModule en el Java Authentication y Authorization Servi... • http://activemq.apache.org/security-advisories.data/CVE-2014-3612-announcement.txt • CWE-287: Improper Authentication CWE-305: Authentication Bypass by Primary Weakness •

CVSS: 4.3EPSS: 4%CPEs: 14EXPL: 0

10 Jul 2013 — Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message." Vulnerabilidad XSS (cross-site scripting) en scheduled.jsp en Apache ActiveMQ v5.8.0 y anteriores permite a atacantes remotos inyectar web scripts arbitrarios o HTML mediante vectores que comprenden el "cron of a message". Fuse MQ Enterprise, based on Apache ActiveMQ, is a standards compliant messaging sys... • http://rhn.redhat.com/errata/RHSA-2013-1029.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 1%CPEs: 14EXPL: 1

10 Jul 2013 — Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092. Vulnerabilidad de XSS en el servlet editor de Portfolio en la aplicación web demo en Apache ActiveMQ anterior a 5.9.0 permite a atacantes remotos inyectar script Web arbitrario o HTML a través del parámetro refresh ... • http://rhn.redhat.com/errata/RHSA-2013-1029.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 1%CPEs: 20EXPL: 0

21 Apr 2013 — The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests. La consola web de Apache ActiveMQ anterior a v5.8.0 no requiere autenticación, lo que permite a atacantes remotos obtener información sensible o causar una denegación de servicio a través de peticiones HTTP. Fuse Message Broker is a messaging platform based on Apache ActiveMQ that provides SOA infrastructure to connect ... • http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.html • CWE-287: Improper Authentication CWE-306: Missing Authentication for Critical Function •

CVSS: 5.3EPSS: 8%CPEs: 20EXPL: 0

21 Apr 2013 — The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests. La configuración por defecto de Apache ActiveMQ anterior a v5.8.0 permite una aplicación Web de ejemplo, la cual permite a atacantes remotos provocar una denegación de servicio (consumo de recursos) a través de peticiones HTTP. Fuse MQ Enterprise, based on Apache ActiveMQ, is a standards compliant messaging sys... • http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.html • CWE-399: Resource Management Errors •

CVSS: 4.3EPSS: 1%CPEs: 20EXPL: 0

21 Apr 2013 — Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en la web de ejemplo ... • http://activemq.apache.org/activemq-580-release.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •