3.5
CVSSv2

CVE-2016-0782

Published: 05/08/2016 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The administration web console in Apache ActiveMQ 5.x prior to 5.11.4, 5.12.x prior to 5.12.3, and 5.13.x prior to 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache activemq 5.3.0

apache activemq 5.11.1

apache activemq 5.8.0

apache activemq 5.4.3

apache activemq 5.4.0

apache activemq 5.5.1

apache activemq 5.12.0

apache activemq 5.4.1

apache activemq 5.13.0

apache activemq 5.9.0

apache activemq 5.11.2

apache activemq 5.11.0

apache activemq 5.11.3

apache activemq 5.3.1

apache activemq 5.13.1

apache activemq 5.2.0

apache activemq 5.7.0

apache activemq 5.12.1

apache activemq 5.10.1

apache activemq 5.10.0

apache activemq 5.1.0

apache activemq 5.5.0

apache activemq 5.3.2

apache activemq 5.10.2

apache activemq 5.9.1

apache activemq 5.12.2

apache activemq 5.6.0

apache activemq 5.4.2

Vendor Advisories

It was found that Apache Active MQ administration web console did not validate input correctly when creating a queue An authenticated attacker could exploit this flaw via cross-site scripting and use it to access sensitive information or further attacks ...