Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown

CVE-2016-3088

Disclosure Date: June 01, 2016 (last updated July 25, 2024)
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Attacker Value
Unknown

CVE-2016-0734

Disclosure Date: April 07, 2016 (last updated November 08, 2023)
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
0
Attacker Value
Unknown

CVE-2015-5254

Disclosure Date: January 08, 2016 (last updated November 08, 2023)
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
0
Attacker Value
Unknown

CVE-2015-6524

Disclosure Date: August 24, 2015 (last updated October 05, 2023)
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
0
Attacker Value
Unknown

CVE-2014-3612

Disclosure Date: August 24, 2015 (last updated October 05, 2023)
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
0
Attacker Value
Unknown

CVE-2015-1830

Disclosure Date: August 19, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-3576

Disclosure Date: August 14, 2015 (last updated November 08, 2023)
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
0
Attacker Value
Unknown

CVE-2014-8110

Disclosure Date: February 12, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1880

Disclosure Date: February 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.
0
Attacker Value
Unknown

CVE-2013-1879

Disclosure Date: July 20, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
0