CVE-2011-4905: Medium severity apache activemq vulnerability
Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
Other sources
Apache ActiveMQ is vulnerable to a denial of service, caused by an error in the failover mechanism when handling an openwire connection request. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the broker service to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2011-4905?
CVE-2011-4905 is a vulnerability in Apache ActiveMQ that allows remote attackers to cause a denial of service.
How does CVE-2011-4905 affect Apache ActiveMQ?
CVE-2011-4905 affects Apache ActiveMQ by causing the broker service to crash.
What is the severity of CVE-2011-4905?
The severity of CVE-2011-4905 is medium.
How can I fix CVE-2011-4905?
To fix CVE-2011-4905, update Apache ActiveMQ to version 5.6.0 or later.
Where can I find more information about CVE-2011-4905?
You can find more information about CVE-2011-4905 at the following references: [reference 1](http://svn.apache.org/viewvc?view=revision&revision=1209700), [reference 2](http://svn.apache.org/viewvc?view=revision&revision=1211844), [reference 3](http://www.securityfocus.com/bid/50904).