CVE-2016-3094
published 2016-06-01CVE-2016-3094: PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
7.83%
94.0th percentile
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_broker-j | <= 6.0.2 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in org.apache.qpid:qpid-broker
osv·2018-10-16
CVE-2016-3094 [MEDIUM] Improper Input Validation in org.apache.qpid:qpid-broker
Improper Input Validation in org.apache.qpid:qpid-broker
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
GHSA
Improper Input Validation in org.apache.qpid:qpid-broker
ghsa·2018-10-16
CVE-2016-3094 [MEDIUM] CWE-20 Improper Input Validation in org.apache.qpid:qpid-broker
Improper Input Validation in org.apache.qpid:qpid-broker
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
OSV
CVE-2016-3094: PlainSaslServer
osv·2016-06-01·CVSS 5.9
CVE-2016-3094 [MEDIUM] CVE-2016-3094: PlainSaslServer
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
Red Hat
qpid-java: crash in PLAIN SASL handler on malformed SASL response
vendor_redhat·2016-05-27·CVSS 5.9
CVE-2016-3094 [MEDIUM] qpid-java: crash in PLAIN SASL handler on malformed SASL response
qpid-java: crash in PLAIN SASL handler on malformed SASL response
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
Statement: This issue affects the versions of qpid-java as shipped with Red Hat Satellite 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: qpid-java (Red Hat Enterprise MRG 2) - Affected
Package: qpid-java (Red Hat Enterprise MRG 3) - Affected
Pac
No detection rules found.
No public exploits indexed.
http://mail-archives.apache.org/mod_mbox/qpid-users/201605.mbox/%3C5748641A.2050701%40gmail.com%3Ehttp://packetstormsecurity.com/files/137215/Apache-Qpid-Java-Broker-6.0.2-Denial-Of-Service.htmlhttp://qpid.apache.org/releases/qpid-java-6.0.3/release-notes.htmlhttp://www.securityfocus.com/archive/1/538507/100/0/threadedhttp://www.securitytracker.com/id/1035982https://issues.apache.org/jira/browse/QPID-7271https://svn.apache.org/viewvc?view=revision&revision=1744403http://mail-archives.apache.org/mod_mbox/qpid-users/201605.mbox/%3C5748641A.2050701%40gmail.com%3Ehttp://packetstormsecurity.com/files/137215/Apache-Qpid-Java-Broker-6.0.2-Denial-Of-Service.htmlhttp://qpid.apache.org/releases/qpid-java-6.0.3/release-notes.htmlhttp://www.securityfocus.com/archive/1/538507/100/0/threadedhttp://www.securitytracker.com/id/1035982https://issues.apache.org/jira/browse/QPID-7271https://svn.apache.org/viewvc?view=revision&revision=1744403
2016-06-01
Published