CVE-2014-3600
ActiveMQ: XXE via XPath expression evaluation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Una vulnerabilidad de XML External Entity (XXE) en Apache ActiveMQ, en versiones 5.x anteriores a la 5,10,1 permite que consumidores remotos provoquen impactos no especificados mediante vectores que implican un selector basado en XPath al eliminar de la cola los mensajes XML.
It was discovered that Apache ActiveMQ performed XML External Entity (XXE) expansion when evaluating XPath expressions. A remote, attacker-controlled consumer able to specify an XPath-based selector to dequeue XML messages from an Apache ActiveMQ broker could use this flaw to read files accessible to the user running the broker, and potentially perform other more advanced XXE attacks.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2015-02-05 CVE Published
- 2023-04-29 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://seclists.org/oss-sec/2015/q1/427 | Mailing List | |
http://www.securityfocus.com/bid/72510 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100722 | Third Party Advisory | |
https://issues.apache.org/jira/browse/AMQ-5333 | Issue Tracking | |
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txt | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2014-3600 | 2015-02-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1133649 | 2015-02-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.0.0 Search vendor "Apache" for product "Activemq" and version "5.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.1.0 Search vendor "Apache" for product "Activemq" and version "5.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.2.0 Search vendor "Apache" for product "Activemq" and version "5.2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.3.0 Search vendor "Apache" for product "Activemq" and version "5.3.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.3.1 Search vendor "Apache" for product "Activemq" and version "5.3.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.3.2 Search vendor "Apache" for product "Activemq" and version "5.3.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.4.0 Search vendor "Apache" for product "Activemq" and version "5.4.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.4.1 Search vendor "Apache" for product "Activemq" and version "5.4.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.4.2 Search vendor "Apache" for product "Activemq" and version "5.4.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.4.3 Search vendor "Apache" for product "Activemq" and version "5.4.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.5.0 Search vendor "Apache" for product "Activemq" and version "5.5.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.5.1 Search vendor "Apache" for product "Activemq" and version "5.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.6.0 Search vendor "Apache" for product "Activemq" and version "5.6.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.7.0 Search vendor "Apache" for product "Activemq" and version "5.7.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.8.0 Search vendor "Apache" for product "Activemq" and version "5.8.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.9.0 Search vendor "Apache" for product "Activemq" and version "5.9.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.9.1 Search vendor "Apache" for product "Activemq" and version "5.9.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Search vendor "Apache" for product "Activemq" | 5.10.0 Search vendor "Apache" for product "Activemq" and version "5.10.0" | - |
Affected
|