CVE-2010-1587: Input Validation
Published Apr 28, 2010
·Updated
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
Affected Software
7 affected componentsFixes available
maven/org.apache.activemq:activemq-web-console>=5.0.0<5.3.2
5.3.2
Apache ActiveMQ=5.0.0
Apache ActiveMQ=5.1.0
Apache ActiveMQ=5.2.0
Apache ActiveMQ=5.3.0
Apache ActiveMQ=5.3.1
Apache ActiveMQ=5.4-snapshot
Remediation
Patch Available
Event History
Apr 28, 2010
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
via GitHub·02:45 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-1587?
CVE-2010-1587 is classified as a medium severity vulnerability.
2
How do I fix CVE-2010-1587?
To fix CVE-2010-1587, upgrade to Apache ActiveMQ version 5.3.2 or later.
3
What systems are affected by CVE-2010-1587?
CVE-2010-1587 affects Apache ActiveMQ versions 5.0.0 to 5.3.1 and all 5.4.x snapshots prior to 5.4.0.
4
What kind of attack does CVE-2010-1587 allow?
CVE-2010-1587 allows remote attackers to read JSP source code by exploiting a URI manipulation vulnerability.
5
What components of Apache ActiveMQ are vulnerable in CVE-2010-1587?
The components affected by CVE-2010-1587 include admin/index.jsp, admin/queues.jsp, and admin/topics.jsp.