We found results for “”
CVE-2015-6524
Good to know:
Date: August 24, 2015
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
Language: Java
Severity Score
Related Resources (7)
Severity Score
Top Fix
Upgrade Version
Upgrade to version org.apache.activemq:activemq-osgi:5.10.1,org.apache.activemq:activemq-all:5.10.1,org.apache.activemq:activemq-web:5.10.1,org.apache.activemq:activemq-jaas:5.10.1,org.apache.activemq:activemq-broker:5.10.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |