Known Vulnerabilities for Jboss A-mq by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Jboss A-mq" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-4104 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j c... | 7.5 - HIGH | 2021-12-14 | 2023-12-22 |
| CVE-2021-3536 | A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, i... | 4.8 - MEDIUM | 2021-05-20 | 2021-05-26 |
| CVE-2021-3425 | A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker appl... | 4.4 - MEDIUM | 2021-06-01 | 2021-06-11 |
| CVE-2020-14379 | A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to de... | 5.6 - MEDIUM | 2022-08-16 | 2022-08-17 |
| CVE-2016-8653 | It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An ... | 5.3 - MEDIUM | 2018-08-01 | 2023-02-12 |
| CVE-2016-8648 | It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed... | 7.2 - HIGH | 2018-08-01 | 2023-02-12 |
| CVE-2015-7559 | It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class.... | 2.7 - LOW | 2019-08-01 | 2023-11-07 |
| CVE-2015-7501 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; E... | 9.8 - CRITICAL | 2017-11-09 | 2020-07-15 |
| CVE-2015-5183 | Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ. | 7.5 - HIGH | 2017-09-25 | 2023-11-07 |
| CVE-2015-5181 | The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript. | 5.4 - MEDIUM | 2017-09-25 | 2017-10-06 |