CVE-2014-3600 – ActiveMQ: XXE via XPath expression evaluation
https://notcve.org/view.php?id=CVE-2014-3600
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages. Una vulnerabilidad de XML External Entity (XXE) en Apache ActiveMQ, en versiones 5.x anteriores a la 5,10,1 permite que consumidores remotos provoquen impactos no especificados mediante vectores que implican un selector basado en XPath al eliminar de la cola los mensajes XML. It was discovered that Apache ActiveMQ performed XML External Entity (XXE) expansion when evaluating XPath expressions. A remote, attacker-controlled consumer able to specify an XPath-based selector to dequeue XML messages from an Apache ActiveMQ broker could use this flaw to read files accessible to the user running the broker, and potentially perform other more advanced XXE attacks. • http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txt http://seclists.org/oss-sec/2015/q1/427 http://www.securityfocus.com/bid/72510 https://exchange.xforce.ibmcloud.com/vulnerabilities/100722 https://issues.apache.org/jira/browse/AMQ-5333 https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E https://access.redhat.com/security/cve/CVE-2014-3600 https://bugzilla.redhat.com/show_bug.cgi?id=1133649 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2013-1880 – ActiveMQ: XSS vulnerability in portfolioPublish demo application
https://notcve.org/view.php?id=CVE-2013-1880
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092. Vulnerabilidad de XSS en el servlet editor de Portfolio en la aplicación web demo en Apache ActiveMQ anterior a 5.9.0 permite a atacantes remotos inyectar script Web arbitrario o HTML a través del parámetro refresh hacia demo/portfolioPublish, una vulnerabilidad distinta que CVE-2012-6092. • http://rhn.redhat.com/errata/RHSA-2013-1029.html http://www.securityfocus.com/bid/65615 https://bugzilla.redhat.com/show_bug.cgi?id=924447 https://issues.apache.org/jira/browse/AMQ-4398 https://access.redhat.com/security/cve/CVE-2013-1880 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1879 – ActiveMQ: XSS vulnerability in scheduled.jsp
https://notcve.org/view.php?id=CVE-2013-1879
Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message." Vulnerabilidad XSS (cross-site scripting) en scheduled.jsp en Apache ActiveMQ v5.8.0 y anteriores permite a atacantes remotos inyectar web scripts arbitrarios o HTML mediante vectores que comprenden el "cron of a message". • http://rhn.redhat.com/errata/RHSA-2013-1029.html http://secunia.com/advisories/54073 http://www.securityfocus.com/bid/61142 https://exchange.xforce.ibmcloud.com/vulnerabilities/85586 https://issues.apache.org/jira/browse/AMQ-4397 https://access.redhat.com/security/cve/CVE-2013-1879 https://bugzilla.redhat.com/show_bug.cgi?id=924446 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-3060 – activemq: Unauthenticated access to web console
https://notcve.org/view.php?id=CVE-2013-3060
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests. La consola web de Apache ActiveMQ anterior a v5.8.0 no requiere autenticación, lo que permite a atacantes remotos obtener información sensible o causar una denegación de servicio a través de peticiones HTTP. • http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.html http://activemq.apache.org/activemq-580-release.html http://rhn.redhat.com/errata/RHSA-2013-1029.html http://rhn.redhat.com/errata/RHSA-2013-1221.html http://www.securityfocus.com/bid/59402 https://fisheye6.atlassian.com/changelog/activemq?cs=1404998 https://issues.apache.org/jira/browse/AMQ-4124 https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version • CWE-287: Improper Authentication CWE-306: Missing Authentication for Critical Function •
CVE-2012-6092 – activemq: Multiple XSS flaws in web demos
https://notcve.org/view.php?id=CVE-2012-6092
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en la web de ejemplo en Apache ActiveMQ anterior a v5.8.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) refresh en PortfolioPublishServlet.java (también conocido como demo/portfolioPublish o Market Data Publisher), o vectores relacionados con (2) logs de depuración, o (3) mensajes de suscripción en webapp/websocket/chat.js. NOTA: AMQ-4124 está cubierto por CVE-2012-6551. • http://activemq.apache.org/activemq-580-release.html http://rhn.redhat.com/errata/RHSA-2013-1029.html http://www.securityfocus.com/bid/59400 https://fisheye6.atlassian.com/changelog/activemq?cs=1399577 https://issues.apache.org/jira/browse/AMQ-4115 https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282 https://access.redhat.com/security/cve/CVE-2012-6092 https://bugzilla.redhat.com/show_bug.cgi?id=955906 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •