First published: Thu Jul 30 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat AMQ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5182 is classified as a medium-severity vulnerability due to its potential for exploitation through cross-site request forgery.
To fix CVE-2015-5182, implement token or referer checks in the A-MQ jolokia API to prevent CSRF attacks.
CVE-2015-5182 affects users of the Red Hat AMQ who utilize the jolokia API.
CVE-2015-5182 enables cross-site request forgery (CSRF) attacks that can execute unauthorized commands.
Yes, CVE-2015-5182 can be relatively easy to exploit due to the lack of security checks in the jolokia API.