CVE-2013-3060
published 2013-04-21CVE-2013-3060: The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a…
PriorityP432medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
6.31%
92.8th percentile
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | <= 5.7.0 | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| debian | activemq | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-3060: activemq - The web console in Apache ActiveMQ before 5.8.0 does not require authentication,...
vendor_debian·2013·CVSS 6.4
CVE-2013-3060 [MEDIUM] CVE-2013-3060: activemq - The web console in Apache ActiveMQ before 5.8.0 does not require authentication,...
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
Red Hat
activemq: Unauthenticated access to web console
vendor_redhat·2012-11-02·CVSS 6.4
CVE-2013-3060 [MEDIUM] CWE-306 activemq: Unauthenticated access to web console
activemq: Unauthenticated access to web console
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
Statement: Fuse ESB Enterprise 7.1.0, Fuse MQ Enterprise 7.1.1, JBoss Fuse 6.0.0 and JBoss A-MQ 6.0.0 all contain the Apache ActiveMQ web console, but it is not deployed by default. The documentation for deploying the web console covers the configuration needed to ensure authentication is enabled, therefore these products are not affected by this flaw. In a future update to these products, the web console will be configured so that authentication is automatically enabled if the web console is deployed, eliminating the need to manually configure it.
A fu
GHSA
Improper Authentication in Apache ActiveMQ
ghsa·2022-05-17
CVE-2013-3060 [MEDIUM] CWE-287 Improper Authentication in Apache ActiveMQ
Improper Authentication in Apache ActiveMQ
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
OSV
Improper Authentication in Apache ActiveMQ
osv·2022-05-17
CVE-2013-3060 [MEDIUM] Improper Authentication in Apache ActiveMQ
Improper Authentication in Apache ActiveMQ
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
No detection rules found.
No public exploits indexed.
http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.htmlhttp://activemq.apache.org/activemq-580-release.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1029.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1221.htmlhttp://www.securityfocus.com/bid/59402https://fisheye6.atlassian.com/changelog/activemq?cs=1404998https://issues.apache.org/jira/browse/AMQ-4124https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.htmlhttp://activemq.apache.org/activemq-580-release.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1029.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1221.htmlhttp://www.securityfocus.com/bid/59402https://fisheye6.atlassian.com/changelog/activemq?cs=1404998https://issues.apache.org/jira/browse/AMQ-4124https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282
2013-04-21
Published