CVE-2014-3600
published 2017-10-27CVE-2014-3600: XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath…
PriorityP356critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
9.85%
95.0th percentile
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | >= 0 < 5.6.0+dfsg1-4 | 5.6.0+dfsg1-4 |
| apache | activemq | >= 0 < 5.6.0+dfsg1-4 | 5.6.0+dfsg1-4 |
| apache | activemq | >= 0 < 5.6.0+dfsg1-4 | 5.6.0+dfsg1-4 |
| debian | activemq | < activemq 5.6.0+dfsg1-4 (bookworm) | activemq 5.6.0+dfsg1-4 (bookworm) |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ActiveMQ: XXE via XPath expression evaluation
vendor_redhat·2015-02-05·CVSS 9.8
CVE-2014-3600 [CRITICAL] CWE-611 ActiveMQ: XXE via XPath expression evaluation
ActiveMQ: XXE via XPath expression evaluation
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
It was discovered that Apache ActiveMQ performed XML External Entity (XXE) expansion when evaluating XPath expressions. A remote, attacker-controlled consumer able to specify an XPath-based selector to dequeue XML messages from an Apache ActiveMQ broker could use this flaw to read files accessible to the user running the broker, and potentially perform other more advanced XXE attacks.
Statement: Fuse ESB 4 and Fuse Message Broker 5.2, 5.3, 5.4 are now in a reduced support phase receiving only Critical impact security fixes. This issue has bee
Debian
CVE-2014-3600: activemq - XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 all...
vendor_debian·2014·CVSS 9.8
CVE-2014-3600 [CRITICAL] CVE-2014-3600: activemq - XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 all...
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Scope: local
bookworm: resolved (fixed in 5.6.0+dfsg1-4)
bullseye: resolved (fixed in 5.6.0+dfsg1-4)
sid: resolved (fixed in 5.6.0+dfsg1-4)
trixie: resolved (fixed in 5.6.0+dfsg1-4)
OSV
Improper Restriction of XML External Entity Reference in Apache ActiveMQ
osv·2022-05-14
CVE-2014-3600 [CRITICAL] Improper Restriction of XML External Entity Reference in Apache ActiveMQ
Improper Restriction of XML External Entity Reference in Apache ActiveMQ
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
GHSA
Improper Restriction of XML External Entity Reference in Apache ActiveMQ
ghsa·2022-05-14
CVE-2014-3600 [CRITICAL] CWE-611 Improper Restriction of XML External Entity Reference in Apache ActiveMQ
Improper Restriction of XML External Entity Reference in Apache ActiveMQ
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
OSV
CVE-2014-3600: XML external entity (XXE) vulnerability in Apache ActiveMQ 5
osv·2017-10-27·CVSS 9.8
CVE-2014-3600 [CRITICAL] CVE-2014-3600: XML external entity (XXE) vulnerability in Apache ActiveMQ 5
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
No detection rules found.
http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txthttp://seclists.org/oss-sec/2015/q1/427http://www.securityfocus.com/bid/72510https://exchange.xforce.ibmcloud.com/vulnerabilities/100722https://issues.apache.org/jira/browse/AMQ-5333https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttp://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txthttp://seclists.org/oss-sec/2015/q1/427http://www.securityfocus.com/bid/72510https://exchange.xforce.ibmcloud.com/vulnerabilities/100722https://issues.apache.org/jira/browse/AMQ-5333https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
2017-10-27
Published