Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache activemq vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2017-15709
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Apache Activemq
4.3
CVSSv2
CVE-2014-8110
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x prior to 5.10.1 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Apache Activemq 5.3.0
Apache Activemq 5.8.0
Apache Activemq 5.4.3
Apache Activemq 5.4.0
Apache Activemq 5.5.1
Apache Activemq 5.4.1
Apache Activemq 5.9.0
Apache Activemq 5.3.1
Apache Activemq 5.2.0
Apache Activemq 5.7.0
Apache Activemq 5.0.0
Apache Activemq 5.10.0
Apache Activemq 5.1.0
Apache Activemq 5.5.0
Apache Activemq 5.3.2
Apache Activemq 5.9.1
Apache Activemq 5.6.0
Apache Activemq 5.4.2
4.3
CVSSv2
CVE-2013-1880
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ prior to 5.9.0 allows remote malicious users to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerabi...
Apache Activemq 5.6.0
Apache Activemq 5.5.1
Apache Activemq 5.3.0
Apache Activemq 5.2.0
Apache Activemq
Apache Activemq 5.7.0
Apache Activemq 5.3.2
Apache Activemq 5.3.1
Apache Activemq 5.5.0
Apache Activemq 5.4.2
Apache Activemq 5.1.0
Apache Activemq 5.0.0
Apache Activemq 5.4.1
Apache Activemq 5.4.0
4.3
CVSSv2
CVE-2013-1879
Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and previous versions allows remote malicious users to inject arbitrary web script or HTML via vectors involving the "cron of a message."
Apache Activemq 5.5.0
Apache Activemq 5.5.1
Apache Activemq 5.0.0
Apache Activemq 5.3.0
Apache Activemq 5.4.2
Apache Activemq 5.2.0
Apache Activemq 5.3.1
Apache Activemq 5.6.0
Apache Activemq 5.3.2
Apache Activemq 5.1.0
Apache Activemq 5.7.0
Apache Activemq
Apache Activemq 5.4.1
Apache Activemq 5.4.0
4.3
CVSSv2
CVE-2012-6092
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ prior to 5.8.0 allow remote malicious users to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publi...
Apache Activemq 5.3.0
Apache Activemq 4.1.0
Apache Activemq 5.4.0
Apache Activemq 5.5.1
Apache Activemq 5.4.1
Apache Activemq 5.3.1
Apache Activemq 5.2.0
Apache Activemq 5.0.0
Apache Activemq 4.0
Apache Activemq 4.0.2
Apache Activemq
Apache Activemq 4.0.1
Apache Activemq 5.1.0
Apache Activemq 5.5.0
Apache Activemq 5.3.2
Apache Activemq 4.1.1
Apache Activemq 5.6.0
Apache Activemq 5.4.2
3.5
CVSSv2
CVE-2010-0684
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ prior to 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Apache Activemq
Apache Activemq 4.0.1
Apache Activemq 4.0
Apache Activemq 3.0
Apache Activemq 2.0
Apache Activemq 5.2.0
Apache Activemq 5.1.0
Apache Activemq 2.1
Apache Activemq 1.5
Apache Activemq 4.1.0
Apache Activemq 4.0.2
Apache Activemq 3.2
Apache Activemq 3.1
Apache Activemq 1.1
Apache Activemq 5.0.0
Apache Activemq 4.1.1
Apache Activemq 3.2.2
Apache Activemq 3.2.1
Apache Activemq 1.4
Apache Activemq 1.3
Apache Activemq 1.2
2.1
CVSSv2
CVE-2020-10727
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this...
Apache Activemq Artemis
Netapp Oncommand Workflow Automation -
NA
CVE-2024-32114
In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with th...
NA
CVE-2022-41678
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to cr...
Apache Activemq
NA
CVE-2023-46604
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire...
Apache Activemq
Apache Activemq Legacy Openwire Module
1 Metasploit module
28 Github repositories
1 Article
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »