Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
BID:72513
Info
Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
| Bugtraq ID: | 72513 |
| Class: | Design Error |
| CVE: |
CVE-2014-3612 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2015 12:00AM |
| Updated: | Aug 12 2015 10:24PM |
| Credit: | Georgi Geshev from MWR Labs and Arun Babu Neelicattu from RedHat |
| Vulnerable: |
Apache Software Foundation Apache ActiveMQ 5.5 Apache Software Foundation Apache ActiveMQ 5.3 Apache Software Foundation Apache ActiveMQ 5.2 Apache Software Foundation Apache ActiveMQ 5.4 |
| Not Vulnerable: | |
Discussion
Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
Apache ActiveMQ is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Apache ActiveMQ is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Exploit / POC
Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
References
Apache ActiveMQ CVE-2014-3612 LDAP Authentication Bypass Vulnerability
References:
References:
- Apache ActiveMQ - Homepage (Apache)