Vulnerabilities
Vulnerable Software
Apache:  >> Activemq  >> 5.15.8  Security Vulnerabilities
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
CVSS Score
6.1
EPSS Score
0.062
Published
2020-05-14
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
CVSS Score
9.8
EPSS Score
0.844
Published
2019-05-15
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
CVSS Score
7.5
EPSS Score
0.124
Published
2019-03-28


Contact Us

Shodan ® - All rights reserved