CVE-2015-7559

LOW

Apache ActiveMQ < 5.14.5 - Denial of Service via Remote Shutdown Command

Title source: llm
STIX 2.1

Description

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

References (2)

Core 2
Core References
Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-7559

Scores

CVSS v3 2.7
EPSS 0.0008
EPSS Percentile 23.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-306 CWE-20
Status published
Products (5)
apache/activemq < 5.14.5
org.apache.activemq/activemq-client 0 - 5.14.5Maven
redhat/jboss_a-mq 6.2.1
redhat/jboss_a-mq 6.3
redhat/jboss_fuse 6.3
Published Aug 01, 2019
Tracked Since Feb 18, 2026