CVE-2016-4432

Severity
9.1CRITICAL
EPSS
0.4%
top 39.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 1
Latest updateOct 16

Description

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Patches

🔴Vulnerability Details

4
OSV
AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication2018-10-16
GHSA
AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication2018-10-16
CVEList
CVE-2016-4432: The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 62016-06-01
OSV
CVE-2016-4432: The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 62016-06-01

📋Vendor Advisories

1
Red Hat
qpid-java: Authentication bypass2016-05-27

💬Community

1
Bugzilla
CVE-2016-4432 qpid-java: Authentication bypass2016-05-30
CVE-2016-4432 (CRITICAL CVSS 9.1) | The AMQP 0-8 | cvebase.io