First published: Fri Jul 31 2015(Updated: )
Console: CORS headers set to allow all in Red Hat AMQ.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Red Hat AMQ | <6.2.1. | 6.2.1. |
Red Hat AMQ | <6.2.1 | |
Red Hat JBoss Enterprise Web Server | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-5184 is classified as medium due to its potential to expose sensitive information through unrestricted CORS headers.
To fix CVE-2015-5184, update Red Hat AMQ to version 6.2.1 or later, which addresses the CORS header issue.
CVE-2015-5184 affects Red Hat AMQ versions prior to 6.2.1 and Red Hat JBoss Enterprise Web Server version 1.0.0.
CVE-2015-5184 can facilitate attacks that allow unauthorized access to sensitive information through Cross-Origin Resource Sharing (CORS) misconfiguration.
Yes, CVE-2015-5184 poses a risk of data leakage as it permits unrestricted cross-origin requests that could expose sensitive data.