Show filters
391 Total Results
Displaying 151-160 of 391
Sort by:
Attacker Value
Unknown
CVE-2020-4931
Disclosure Date: February 23, 2021 (last updated November 28, 2024)
IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.
0
Attacker Value
Unknown
CVE-2020-13947
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
0
Attacker Value
Unknown
CVE-2021-26117
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
0
Attacker Value
Unknown
CVE-2021-26118
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.
0
Attacker Value
Unknown
CVE-2020-4682
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.
0
Attacker Value
Unknown
CVE-2020-4766
Disclosure Date: January 21, 2021 (last updated February 22, 2025)
IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources. IBM X-Force ID: 188093.
0
Attacker Value
Unknown
CVE-2020-4869
Disclosure Date: January 08, 2021 (last updated February 22, 2025)
IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.
0
Attacker Value
Unknown
CVE-2020-4870
Disclosure Date: December 18, 2020 (last updated November 28, 2024)
IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.
0
Attacker Value
Unknown
CVE-2020-35196
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
0
Attacker Value
Unknown
CVE-2020-35149
Disclosure Date: December 11, 2020 (last updated November 28, 2024)
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
0