First published: Wed Aug 19 2015(Updated: )
Apache ActiveMQ could allow a remote attacker to traverse directories on the system, caused by an error in the fileserver upload/download functionality. By placing a jsp file in the admin console, an attacker could exploit this vulnerability to execute arbitrary shell commands on the system.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Directory Suite VA | <=8.0.1-8.0.1.19 | |
Apache ActiveMQ | =5.0.0 | |
Apache ActiveMQ | =5.1.0 | |
Apache ActiveMQ | =5.2.0 | |
Apache ActiveMQ | =5.3.0 | |
Apache ActiveMQ | =5.3.1 | |
Apache ActiveMQ | =5.3.2 | |
Apache ActiveMQ | =5.4.0 | |
Apache ActiveMQ | =5.4.1 | |
Apache ActiveMQ | =5.4.2 | |
Apache ActiveMQ | =5.4.3 | |
Apache ActiveMQ | =5.5.0 | |
Apache ActiveMQ | =5.5.1 | |
Apache ActiveMQ | =5.6.0 | |
Apache ActiveMQ | =5.7.0 | |
Apache ActiveMQ | =5.8.0 | |
Apache ActiveMQ | =5.9.0 | |
Apache ActiveMQ | =5.9.1 | |
Apache ActiveMQ | =5.10.0 | |
Apache ActiveMQ | =5.10.1 | |
Apache ActiveMQ | =5.10.2 | |
Apache ActiveMQ | =5.11.0 | |
Apache ActiveMQ | =5.11.1 | |
Microsoft Windows | ||
maven/org.apache.activemq:activemq-client | >=5.0.0<=5.11.1 | 5.11.2 |
All of | ||
Any of | ||
Apache ActiveMQ | =5.0.0 | |
Apache ActiveMQ | =5.1.0 | |
Apache ActiveMQ | =5.2.0 | |
Apache ActiveMQ | =5.3.0 | |
Apache ActiveMQ | =5.3.1 | |
Apache ActiveMQ | =5.3.2 | |
Apache ActiveMQ | =5.4.0 | |
Apache ActiveMQ | =5.4.1 | |
Apache ActiveMQ | =5.4.2 | |
Apache ActiveMQ | =5.4.3 | |
Apache ActiveMQ | =5.5.0 | |
Apache ActiveMQ | =5.5.1 | |
Apache ActiveMQ | =5.6.0 | |
Apache ActiveMQ | =5.7.0 | |
Apache ActiveMQ | =5.8.0 | |
Apache ActiveMQ | =5.9.0 | |
Apache ActiveMQ | =5.9.1 | |
Apache ActiveMQ | =5.10.0 | |
Apache ActiveMQ | =5.10.1 | |
Apache ActiveMQ | =5.10.2 | |
Apache ActiveMQ | =5.11.0 | |
Apache ActiveMQ | =5.11.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1830 is a directory traversal vulnerability in Apache ActiveMQ that allows a remote attacker to execute arbitrary shell commands on the system.
CVE-2015-1830 has a severity level of 9.8, which is considered critical.
Apache ActiveMQ versions 5.0.0 to 5.11.1 are affected by CVE-2015-1830.
To fix CVE-2015-1830, it is recommended to upgrade to a patched version of Apache ActiveMQ.
More information about CVE-2015-1830 can be found on the Apache ActiveMQ website and security advisory pages.