5
CVSSv2

CVE-2015-6524

Published: 24/08/2015 Updated: 09/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x prior to 5.10.1 allows wildcard operators in usernames, which allows remote malicious users to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 22

fedoraproject fedora 23

apache activemq 5.0.0

apache activemq 5.4.0

apache activemq 5.4.2

apache activemq 5.7.0

apache activemq 5.9.0

apache activemq 5.4.3

apache activemq 5.5.0

apache activemq 5.5.1

apache activemq 5.6.0

apache activemq 5.10.0

apache activemq 5.2.0

apache activemq 5.3.0

apache activemq 5.3.1

apache activemq 5.1.0

apache activemq 5.3.2

apache activemq 5.4.1

apache activemq 5.8.0

apache activemq 5.9.1

Vendor Advisories

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5x before 5101 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types ...