Severity
5.0MEDIUM
EPSS
8.4%
top 7.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 21
Latest updateMay 17

Description

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

🔴Vulnerability Details

4
GHSA
Apache ActiveMQ default configuration subject to denial of service2022-05-17
OSV
Apache ActiveMQ default configuration subject to denial of service2022-05-17
GHSA
Cross-site Scripting in Apache ActiveMQ2022-05-17
CVEList
CVE-2012-6551: The default configuration of Apache ActiveMQ before 52013-04-21

📋Vendor Advisories

3
Red Hat
activemq: DoS by resource consumption via HTTP requests to sample webapp2012-11-02
Red Hat
activemq: Multiple XSS flaws in web demos2012-10-18
Debian
CVE-2012-6551: activemq - The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web a...2012

💬Community

2
Bugzilla
CVE-2012-6551 activemq: DoS by resource consumption via HTTP requests to sample webapp2013-04-24
Bugzilla
CVE-2012-6092 activemq: Multiple XSS flaws in web demos2013-04-24
CVE-2012-6551 (MEDIUM CVSS 5) | The default configuration of Apache | cvebase.io