CVE-2012-6551
published 2013-04-21CVE-2012-6551: The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.67%
94.0th percentile
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | <= 5.7.0 | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| debian | activemq | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache ActiveMQ default configuration subject to denial of service
ghsa·2022-05-17
CVE-2012-6551 [MEDIUM] CWE-400 Apache ActiveMQ default configuration subject to denial of service
Apache ActiveMQ default configuration subject to denial of service
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
OSV
Cross-site Scripting in Apache ActiveMQ
osv·2022-05-17·CVSS 5.0
CVE-2012-6092 [MEDIUM] Cross-site Scripting in Apache ActiveMQ
Cross-site Scripting in Apache ActiveMQ
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
OSV
Apache ActiveMQ default configuration subject to denial of service
osv·2022-05-17
CVE-2012-6551 [MEDIUM] Apache ActiveMQ default configuration subject to denial of service
Apache ActiveMQ default configuration subject to denial of service
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
GHSA
Cross-site Scripting in Apache ActiveMQ
ghsa·2022-05-17·CVSS 5.0
CVE-2012-6092 [MEDIUM] CWE-79 Cross-site Scripting in Apache ActiveMQ
Cross-site Scripting in Apache ActiveMQ
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
Red Hat
activemq: DoS by resource consumption via HTTP requests to sample webapp
vendor_redhat·2012-11-02·CVSS 5.0
CVE-2012-6551 [MEDIUM] activemq: DoS by resource consumption via HTTP requests to sample webapp
activemq: DoS by resource consumption via HTTP requests to sample webapp
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
Package: activemq (OpenShift Enterprise 1) - Not affected
Package: activemq (Red Hat JBoss SOA Platform 4) - Will not fix
Red Hat
activemq: Multiple XSS flaws in web demos
vendor_redhat·2012-10-18·CVSS 4.3
CVE-2012-6092 [MEDIUM] CWE-79 activemq: Multiple XSS flaws in web demos
activemq: Multiple XSS flaws in web demos
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
Package: activemq (OpenShift Enterprise 1) - Not affected
Package: activemq (Red Hat JBoss SOA Platform 4) - Will not fix
Debian
CVE-2012-6551: activemq - The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web a...
vendor_debian·2012·CVSS 5.0
CVE-2012-6551 [MEDIUM] CVE-2012-6551: activemq - The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web a...
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
Debian
CVE-2012-6092: activemq - Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache A...
vendor_debian·2012·CVSS 4.3
CVE-2012-6092 [MEDIUM] CVE-2012-6092: activemq - Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache A...
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6551 activemq: DoS by resource consumption via HTTP requests to sample webapp
bugzilla·2013-04-24·CVSS 5.0
CVE-2012-6551 [MEDIUM] CVE-2012-6551 activemq: DoS by resource consumption via HTTP requests to sample webapp
CVE-2012-6551 activemq: DoS by resource consumption via HTTP requests to sample webapp
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6551
Discussion:
This issue has been addressed in following products:
Fuse MQ Enterprise 7.1.0
Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html
Bugzilla
CVE-2012-6092 activemq: Multiple XSS flaws in web demos
bugzilla·2013-04-24·CVSS 4.3
CVE-2012-6092 [MEDIUM] CVE-2012-6092 activemq: Multiple XSS flaws in web demos
CVE-2012-6092 activemq: Multiple XSS flaws in web demos
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6092
Discussion:
This issue has been addressed in following products:
Fuse MQ Enterprise 7.1.0
Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html
http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.htmlhttp://activemq.apache.org/activemq-580-release.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1029.htmlhttp://www.securityfocus.com/bid/59401https://fisheye6.atlassian.com/changelog/activemq?cs=1404998https://issues.apache.org/jira/browse/AMQ-4124https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.htmlhttp://activemq.apache.org/activemq-580-release.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1029.htmlhttp://www.securityfocus.com/bid/59401https://fisheye6.atlassian.com/changelog/activemq?cs=1404998https://issues.apache.org/jira/browse/AMQ-4124https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282
2013-04-21
Published