CVE-2014-3576

HIGH

Apache Activemq < 5.10.0 - Access Control

Title source: rule

Description

The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.

Exploits (1)

nomisec WORKING POC
by shoucheng3 · poc
https://github.com/shoucheng3/apache__activemq_CVE-2014-3576_5-10-1

Scores

CVSS v3 7.5
EPSS 0.3820
EPSS Percentile 97.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-264
Status published
Products (7)
apache/activemq < 5.10.0
oracle/business_intelligence_publisher 12.2.1.0.0
oracle/fusion_middleware 8.1
oracle/fusion_middleware 9.0
oracle/fusion_middleware 11.1.1.7.4
oracle/fusion_middleware 12.1.3.0.0
org.apache.activemq/activemq-client 0 - 5.11.0Maven
Published Aug 14, 2015
Tracked Since Feb 18, 2026