9.8
CVSSv3

CVE-2014-3579

Published: 27/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x prior to 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

Vulnerable Product Search on Vulmon Subscribe to Product

apache activemq apollo 1.7

apache activemq apollo 1.6

apache activemq apollo 1.5

apache activemq apollo 1.4

apache activemq apollo 1.3

apache activemq apollo 1.2

apache activemq apollo 1.1

apache activemq apollo 1.0

Vendor Advisories

It was discovered that Apache ActiveMQ Apollo performed XML External Entity (XXE) expansion when evaluating XPath expressions A remote, attacker-controlled consumer able to specify an XPath-based selector to dequeue XML messages from an Apache ActiveMQ Apollo broker could use this flaw to read files accessible to the user running the broker, and p ...