CVE-2016-3094
MEDIUMApache Qpid Broker-j < 6.0.2 - Authentication Bypass
Title source: ruleDescription
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
References (7)
Scores
CVSS v3
5.9
EPSS
0.0099
EPSS Percentile
76.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-287
CWE-20
Status
draft
Affected Products (2)
apache/qpid_broker-j
< 6.0.2
org.apache.qpid/qpid-broker
< 6.0.3Maven
Timeline
Published
Jun 01, 2016
Tracked Since
Feb 18, 2026