Vulnerabilities > CVE-2012-6551 - Resource Management Errors vulnerability in Apache Activemq

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
apache
CWE-399

Summary

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.

Common Weakness Enumeration (CWE)

Redhat

advisories
rhsa
idRHSA-2013:1029

Seebug

bulletinFamilyexploit
descriptionCVE ID:CVE-2012-6551 Apache ActiveMQ是一款开源消息总线,支持JMS1.1和J2EE 1.4规范的JMS Provider实现。 默认配置下Apache ActiveMQ启用一个简单的WEB应用,允许远程攻击者利用漏洞提交HTTP请求消耗broker资源而造成拒绝服务攻击。 0 Apache ActiveMQ 5.8.0之前版本 厂商解决方案 Apache ActiveMQ 5.8.0已经修复此漏洞,建议用户下载更新: https://activemq.apache.org/
idSSV:60762
last seen2017-11-19
modified2013-04-24
published2013-04-24
reporterRoot
titleApache ActiveMQ CVE-2012-6551远程拒绝服务漏洞