First published: Fri Oct 27 2017(Updated: )
Apache ActiveMQ could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when processing XML data. By sending specially-crafted XML data to specify an XPath based selector, an attacker could exploit this vulnerability to obtain sensitive information.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ActiveMQ | =5.0.0 | |
Apache ActiveMQ | =5.1.0 | |
Apache ActiveMQ | =5.2.0 | |
Apache ActiveMQ | =5.3.0 | |
Apache ActiveMQ | =5.3.1 | |
Apache ActiveMQ | =5.3.2 | |
Apache ActiveMQ | =5.4.0 | |
Apache ActiveMQ | =5.4.1 | |
Apache ActiveMQ | =5.4.2 | |
Apache ActiveMQ | =5.4.3 | |
Apache ActiveMQ | =5.5.0 | |
Apache ActiveMQ | =5.5.1 | |
Apache ActiveMQ | =5.6.0 | |
Apache ActiveMQ | =5.7.0 | |
Apache ActiveMQ | =5.8.0 | |
Apache ActiveMQ | =5.9.0 | |
Apache ActiveMQ | =5.9.1 | |
Apache ActiveMQ | =5.10.0 | |
maven/org.apache.activemq:activemq-broker | >=5.0.0<5.10.1 | 5.10.1 |
maven/org.apache.activemq:activemq-client | >=5.0.0<5.10.1 | 5.10.1 |
IBM Security Directory Suite VA | <=8.0.1-8.0.1.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3600 is an XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 that allows remote consumers to obtain sensitive information.
CVE-2014-3600 occurs due to an XML External Entity Injection (XXE) error when processing XML data.
CVE-2014-3600 has a severity rating of 9.8 (critical).
The affected software versions of CVE-2014-3600 include Apache ActiveMQ 5.0.0 to 5.10.0.
To fix CVE-2014-3600, you should upgrade to Apache ActiveMQ 5.10.1 or a later version.