CVE-2016-4432

CRITICAL

Apache Qpid Java <6.0.3 - Auth Bypass

Title source: llm

Description

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

Scores

CVSS v3 9.1
EPSS 0.0039
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-287
Status draft

Affected Products (3)

apache/qpid_broker-j < 6.0.3
org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol < 6.0.3Maven
org.apache.qpid/qpid-broker-plugins-amqp-1-0-protocol < 6.0.3Maven

Timeline

Published Jun 01, 2016
Tracked Since Feb 18, 2026