CVE-2015-7559
01.08.2019, 14:15
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.Enginsight
Vendor | Product | Version |
---|---|---|
apache | activemq | 𝑥 < 5.14.5 |
apache | activemq | 5.15.0 ≤ 𝑥 < 5.15.5 |
redhat | jboss_a-mq | 6.2.1 |
redhat | jboss_a-mq | 6.3 |
redhat | jboss_fuse | 6.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
activemq |
|
Common Weakness Enumeration
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.