CVE-2014-3612
Summary
| CVE | CVE-2014-3612 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-24 14:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Activemq | 5.0.0 | All | All | All |
| Application | Apache | Activemq | 5.1.0 | All | All | All |
| Application | Apache | Activemq | 5.10.0 | All | All | All |
| Application | Apache | Activemq | 5.2.0 | All | All | All |
| Application | Apache | Activemq | 5.3.0 | All | All | All |
| Application | Apache | Activemq | 5.3.1 | All | All | All |
| Application | Apache | Activemq | 5.3.2 | All | All | All |
| Application | Apache | Activemq | 5.4.0 | All | All | All |
| Application | Apache | Activemq | 5.4.1 | All | All | All |
| Application | Apache | Activemq | 5.4.2 | All | All | All |
| Application | Apache | Activemq | 5.4.3 | All | All | All |
| Application | Apache | Activemq | 5.5.0 | All | All | All |
| Application | Apache | Activemq | 5.5.1 | All | All | All |
| Application | Apache | Activemq | 5.6.0 | All | All | All |
| Application | Apache | Activemq | 5.7.0 | All | All | All |
| Application | Apache | Activemq | 5.8.0 | All | All | All |
| Application | Apache | Activemq | 5.9.0 | All | All | All |
| Application | Apache | Activemq | 5.9.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-sec: [ANNOUNCE] CVE-2014-3600, CVE-2014-3612 and CVE-2014-8110 - Apache ActiveMQ vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| activemq.apache.org/security-advisories.data/CVE-2014-3612-announcement.txt | af854a3a-2127-422b-91ae-364da2661108 | activemq.apache.org | Vendor Advisory |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.