CVE-2016-4432
CRITICALApache Qpid Java <6.0.3 - Auth Bypass
Title source: llmDescription
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.
References (7)
Scores
CVSS v3
9.1
EPSS
0.0039
EPSS Percentile
59.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-287
Status
draft
Affected Products (3)
apache/qpid_broker-j
< 6.0.3
org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol
< 6.0.3Maven
org.apache.qpid/qpid-broker-plugins-amqp-1-0-protocol
< 6.0.3Maven
Timeline
Published
Jun 01, 2016
Tracked Since
Feb 18, 2026