Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
BID:72510
Info
Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
| Bugtraq ID: | 72510 |
| Class: | Design Error |
| CVE: |
CVE-2014-3600 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2015 12:00AM |
| Updated: | Aug 12 2015 10:24PM |
| Credit: | Georgi Geshev |
| Vulnerable: |
Apache Software Foundation Apache ActiveMQ 5.5 Apache Software Foundation Apache ActiveMQ 5.3 Apache Software Foundation Apache ActiveMQ 5.2 Apache Software Foundation Apache ActiveMQ 5.4 |
| Not Vulnerable: | |
Discussion
Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
Apache ActiveMQ is prone to an XML External Entity injection vulnerability because the application fails to properly handle external XML data.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Apache ActiveMQ 5.0.0 through 5.10.0 are vulnerable.
Apache ActiveMQ is prone to an XML External Entity injection vulnerability because the application fails to properly handle external XML data.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Apache ActiveMQ 5.0.0 through 5.10.0 are vulnerable.
Solution / Fix
Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache ActiveMQ CVE-2014-3600 XML External Entity Injection Vulnerability
References:
References:
- Apache ActiveMQ - Homepage (Apache)