CVE-2015-5184: High severity red hat amq vulnerability
Console: CORS headers set to allow all in Red Hat AMQ.
Other sources
It was found that A-MQ's Hawtio console setting for the Access-Control-Allow-Origin header permits unrestricted sharing. An attacker could use this flaw to access sensitive information or perform other attacks.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5184?
The severity of CVE-2015-5184 is classified as medium due to its potential to expose sensitive information through unrestricted CORS headers.
How do I fix CVE-2015-5184?
To fix CVE-2015-5184, update Red Hat AMQ to version 6.2.1 or later, which addresses the CORS header issue.
What systems are affected by CVE-2015-5184?
CVE-2015-5184 affects Red Hat AMQ versions prior to 6.2.1 and Red Hat JBoss Enterprise Web Server version 1.0.0.
What type of attack can CVE-2015-5184 facilitate?
CVE-2015-5184 can facilitate attacks that allow unauthorized access to sensitive information through Cross-Origin Resource Sharing (CORS) misconfiguration.
Is there a risk of data leakage due to CVE-2015-5184?
Yes, CVE-2015-5184 poses a risk of data leakage as it permits unrestricted cross-origin requests that could expose sensitive data.