CVE-2014-3576
published 2015-08-14CVE-2014-3576: The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
12.79%
95.8th percentile
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | <= 5.10.0 | — |
| apache | activemq | >= 0 < 5.6.0+dfsg1-4+deb8u1 | 5.6.0+dfsg1-4+deb8u1 |
| apache | activemq | >= 0 < 5.6.0+dfsg1-4+deb8u1 | 5.6.0+dfsg1-4+deb8u1 |
| apache | activemq | >= 0 < 5.6.0+dfsg1-4+deb8u1 | 5.6.0+dfsg1-4+deb8u1 |
| debian | activemq | < activemq 5.6.0+dfsg1-4+deb8u1 (bookworm) | activemq 5.6.0+dfsg1-4+deb8u1 (bookworm) |
| oracle | business_intelligence_publisher | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-3576: activemq - The processControlCommand function in broker/TransportConnection.java in Apache ...
vendor_debian·2014·CVSS 7.5
CVE-2014-3576 [HIGH] CVE-2014-3576: activemq - The processControlCommand function in broker/TransportConnection.java in Apache ...
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
Scope: local
bookworm: resolved (fixed in 5.6.0+dfsg1-4+deb8u1)
bullseye: resolved (fixed in 5.6.0+dfsg1-4+deb8u1)
sid: resolved (fixed in 5.6.0+dfsg1-4+deb8u1)
trixie: resolved (fixed in 5.6.0+dfsg1-4+deb8u1)
GHSA
Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ
ghsa·2022-05-14
CVE-2014-3576 [HIGH] CWE-78 Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ
Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
OSV
Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ
osv·2022-05-14
CVE-2014-3576 [HIGH] Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ
Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
OSV
CVE-2014-3576: The processControlCommand function in broker/TransportConnection
osv·2015-08-14·CVSS 7.5
CVE-2014-3576 [HIGH] CVE-2014-3576: The processControlCommand function in broker/TransportConnection
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
No detection rules found.
No public exploits indexed.
http://activemq.2283324.n4.nabble.com/About-CVE-2014-3576-tp4699628.htmlhttp://packetstormsecurity.com/files/134274/Apache-ActiveMQ-5.10.1-Denial-Of-Service.htmlhttp://www.debian.org/security/2015/dsa-3330http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/archive/1/536862/100/0/threadedhttp://www.securityfocus.com/bid/76272http://www.securitytracker.com/id/1033898https://github.com/apache/activemq/commit/00921f2https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttp://activemq.2283324.n4.nabble.com/About-CVE-2014-3576-tp4699628.htmlhttp://packetstormsecurity.com/files/134274/Apache-ActiveMQ-5.10.1-Denial-Of-Service.htmlhttp://www.debian.org/security/2015/dsa-3330http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/archive/1/536862/100/0/threadedhttp://www.securityfocus.com/bid/76272http://www.securitytracker.com/id/1033898https://github.com/apache/activemq/commit/00921f2https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
2015-08-14
Published