Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Jboss_a\-Mq
(Redhat)Repositories | https://github.com/jboss-fuse/fuse |
#Vulnerabilities | 17 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2017-09-25 | CVE-2015-5183 | Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ. | Amq, Jboss_a\-Mq, Jboss_enterprise_web_server | 7.5 | ||
2019-08-01 | CVE-2015-7559 | It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client. | Activemq, Jboss_a\-Mq, Jboss_fuse | 2.7 | ||
2013-09-30 | CVE-2013-4372 | Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page. | Jboss_a\-Mq, Jboss_fuse | N/A | ||
2018-08-01 | CVE-2016-8648 | It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath. | Jboss_a\-Mq, Jboss_fuse | 7.2 | ||
2018-08-01 | CVE-2016-8653 | It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack. | Jboss_a\-Mq, Jboss_fuse | 5.3 | ||
2017-09-25 | CVE-2015-5181 | The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript. | Jboss_a\-Mq | 5.4 | ||
2014-04-17 | CVE-2014-0085 | JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log. | Jboss_a\-Mq, Jboss_fuse | N/A |