7.5
CVSSv3

CVE-2019-0200

Published: 06/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated malicious user to crash the broker instance by sending specially crafted commands using AMQP protocol versions below 1.0 (AMQP 0-8, 0-9, 0-91 and 0-10). Users of Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 utilizing AMQP protocols 0-8, 0-9, 0-91, 0-10 must upgrade to Qpid Broker-J versions 7.0.7 or 7.1.1 or later.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache qpid broker-j

apache qpid broker-j 7.1.0

Mailing Lists

CVE-2019-0200: Apache Qpid Broker-J Denial of Service due to malformed AMQP 0-8 to 0-10 commands Severity: Critical Vendor: The Apache Software Foundation Versions Affected: 600-706 (inclusive), 710 Description: A Denial of Service vulnerability [1] was found in Apache Qpid Broker-J versions 600-706 (inclusive) and 710 which allows ...