5
CVSSv2

CVE-2012-3467

Published: 27/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache QPID 0.14, 0.16, and previous versions uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote malicious users to bypass authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache qpid

apache qpid 0.6

apache qpid 0.14

apache qpid 0.5

Vendor Advisories

Synopsis Moderate: Red Hat Enterprise MRG Messaging 22 update Type/Severity Security Advisory: Moderate Topic Updated Messaging component packages that fix one security issue, multiplebugs, and add various enhancements are now available for Red Hat EnterpriseMRG 22 for Red Hat Enterprise Linux 6The Red H ...
Synopsis Moderate: Red Hat Enterprise MRG Messaging 22 update Type/Severity Security Advisory: Moderate Topic Updated Messaging component packages that fix two security issues, multiplebugs, and add various enhancements are now available for Red Hat EnterpriseMRG 22 for Red Hat Enterprise Linux 5The Red ...