CVE-2016-0782
published 2016-08-05CVE-2016-0782: The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to…
PriorityP429medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
6.07%
92.6th percentile
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian5.4LOW
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
activemq: Cross-site scripting vulnerabilities in web console
vendor_redhat·2016-03-10·CVSS 5.4
CVE-2016-0782 [MEDIUM] CWE-79 activemq: Cross-site scripting vulnerabilities in web console
activemq: Cross-site scripting vulnerabilities in web console
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
It was found that Apache Active MQ administration web console did not validate input correctly when creating a queue. An authenticated attacker could exploit this flaw via cross-site scripting and use it to access sensitive information or further attacks.
Package: activemq (Red Hat JBoss A-MQ 6) - Affected
Package: activemq (Red Hat JBoss Fuse 6) - Not affected
Package: activemq (Red Hat JBoss Fuse Service Works 6.0.0) - W
Debian
CVE-2016-0782: activemq - The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x befo...
vendor_debian·2016·CVSS 5.4
CVE-2016-0782 [MEDIUM] CVE-2016-0782: activemq - The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x befo...
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
Scope: local
bookworm: resolved (fixed in 5.13.2+dfsg-1)
bullseye: resolved (fixed in 5.13.2+dfsg-1)
sid: resolved (fixed in 5.13.2+dfsg-1)
trixie: resolved (fixed in 5.13.2+dfsg-1)
OSV
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
osv·2022-05-14
CVE-2016-0782 [MEDIUM] Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
GHSA
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
ghsa·2022-05-14
CVE-2016-0782 [MEDIUM] CWE-79 Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
OSV
CVE-2016-0782: The administration web console in Apache ActiveMQ 5
osv·2016-08-05·CVSS 5.4
CVE-2016-0782 [MEDIUM] CVE-2016-0782: The administration web console in Apache ActiveMQ 5
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0782 activemq: Cross-site scripting vulnerabilities in web console
bugzilla·2016-03-14·CVSS 5.4
CVE-2016-0782 [MEDIUM] CVE-2016-0782 activemq: Cross-site scripting vulnerabilities in web console
CVE-2016-0782 activemq: Cross-site scripting vulnerabilities in web console
Several instances of cross-site scripting vulnerabilities were identified to be present in the web based administration console as well as the ability to trigger a Java memory dump into an arbitrary folder. The root cause of these issues are improper user data output validation and incorrect permissions configured on Jolokia.
Affected versions: ActiveMQ 5.0.0 - 5.13.1
External Reference:
http://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txt
Discussion:
Created activemq tracking bugs for this issue:
Affects: fedora-all [bug 1317522]
---
https://issues.jboss.org/browse/ENTMQ-1586 was opened to track
---
This issue has been addressed in the following products:
JBoss Fuse 6.2.1
Bugzilla
CVE-2016-0734 CVE-2016-0782 activemq: various flaws [fedora-all]
bugzilla·2016-03-14·CVSS 6.1
CVE-2016-0734 [MEDIUM] CVE-2016-0734 CVE-2016-0782 activemq: various flaws [fedora-all]
CVE-2016-0734 CVE-2016-0782 activemq: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
http://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txthttp://packetstormsecurity.com/files/136215/Apache-ActiveMQ-5.13.0-Cross-Site-Scripting.htmlhttp://www.securityfocus.com/archive/1/537760/100/0/threadedhttp://www.securitytracker.com/id/1035328https://access.redhat.com/errata/RHSA-2016:1424https://bugzilla.redhat.com/show_bug.cgi?id=1317516https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttp://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txthttp://packetstormsecurity.com/files/136215/Apache-ActiveMQ-5.13.0-Cross-Site-Scripting.htmlhttp://www.securityfocus.com/archive/1/537760/100/0/threadedhttp://www.securitytracker.com/id/1035328https://access.redhat.com/errata/RHSA-2016:1424https://bugzilla.redhat.com/show_bug.cgi?id=1317516https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
2016-08-05
Published