CVE-2014-3576: OS Command Injection
Apache ActiveMQ is vulnerable to a denial of service, caused by an error in the processControlCommand function in broker/TransportConnection.java. A remote attacker could use the shutdown command to shutdown the service.
Other sources
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-3576?
CVE-2014-3576 is a vulnerability in Apache ActiveMQ that allows a remote attacker to cause a denial of service by using the shutdown command to shut down the service.
How does CVE-2014-3576 affect Apache ActiveMQ?
CVE-2014-3576 affects Apache ActiveMQ versions up to and including 5.10.0, allowing a remote attacker to shut down the service using the shutdown command.
Which other software is affected by CVE-2014-3576?
Oracle Business Intelligence Publisher, Oracle Fusion Middleware (versions 8.1, 9.0, 11.1.1.7.4, and 12.1.3.0.0), and IBM Security Directory Suite VA (versions 8.0.1-8.0.1.19) are also affected by CVE-2014-3576.
What is the severity of CVE-2014-3576?
CVE-2014-3576 has a severity rating of 7.5 (high).
How can I mitigate the CVE-2014-3576 vulnerability?
To mitigate the CVE-2014-3576 vulnerability, it is recommended to upgrade to a version of Apache ActiveMQ that is not affected, such as version 5.11 or later.