CVE-2013-3060

Apache ActiveMQ <5.8.0 - Info Disclosure/DoS

Title source: llm
STIX 2.1

Description

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/59402
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1029.html
Various Sources x_refsource_confirm
http://activemq.apache.org/activemq-580-release.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1221.html
Various Sources x_refsource_confirm
https://issues.apache.org/jira/browse/AMQ-4124

Scores

EPSS 0.0631
EPSS Percentile 92.7%

Details

CWE
CWE-287
Status published
Products (19)
apache/activemq 4.0 (3 CPE variants)
apache/activemq 4.0.1
apache/activemq 4.0.2
apache/activemq 4.1.0
apache/activemq 4.1.1
apache/activemq 5.0.0
apache/activemq 5.1.0
apache/activemq 5.2.0
apache/activemq 5.3.0
apache/activemq 5.3.1
... and 9 more
Published Apr 21, 2013
Tracked Since Feb 18, 2026