CVE-2014-3612: High severity apache activemq vulnerability
Apache ActiveMQ could allow a remote authenticated attacker to bypass security restrictions, caused by an error in the LDAPLoginModule implementation. By sending an empty password, an attacker could exploit this vulnerability to bypass the authentication mechanism of an application using LDAPLoginModule and assume the role of another user.
Other sources
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2014-3612.
What is the affected software?
The affected software is Apache ActiveMQ versions 5.0.0 to 5.10.1.
How does the vulnerability allow bypassing security restrictions?
The vulnerability allows remote attackers to bypass authentication by logging in with an empty password and valid username, triggering an unauthenticated bind.
What is the severity of CVE-2014-3612?
The severity of CVE-2014-3612 is high with a CVSS score of 7.5.
Where can I find more information about CVE-2014-3612?
More information about CVE-2014-3612 can be found at the following references: [Reference 1](http://activemq.apache.org/security-advisories.data/CVE-2014-3612-announcement.txt), [Reference 2](http://rhn.redhat.com/errata/RHSA-2015-0137.html), [Reference 3](http://rhn.redhat.com/errata/RHSA-2015-0138.html).