First published: Mon Aug 24 2015(Updated: )
Apache ActiveMQ is vulnerable to a brute force attack, caused by an error in the LDAPLoginModule implementation. An attacker could exploit this vulnerability using the wildcard in usernames to obtain user credentials.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Directory Suite VA | <=8.0.1-8.0.1.19 | |
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 | |
Apache ActiveMQ | =5.0.0 | |
Apache ActiveMQ | =5.1.0 | |
Apache ActiveMQ | =5.2.0 | |
Apache ActiveMQ | =5.3.0 | |
Apache ActiveMQ | =5.3.1 | |
Apache ActiveMQ | =5.3.2 | |
Apache ActiveMQ | =5.4.0 | |
Apache ActiveMQ | =5.4.1 | |
Apache ActiveMQ | =5.4.2 | |
Apache ActiveMQ | =5.4.3 | |
Apache ActiveMQ | =5.5.0 | |
Apache ActiveMQ | =5.5.1 | |
Apache ActiveMQ | =5.6.0 | |
Apache ActiveMQ | =5.7.0 | |
Apache ActiveMQ | =5.8.0 | |
Apache ActiveMQ | =5.9.0 | |
Apache ActiveMQ | =5.9.1 | |
Apache ActiveMQ | =5.10.0 | |
maven/org.apache.activemq:activemq-jaas | >=5.0.0<=5.10.1 | 5.10.2 |
maven/org.apache.activemq:activemq-broker | >=5.0.0<=5.10.1 | 5.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6524 is a vulnerability in Apache ActiveMQ that allows remote attackers to obtain credentials via a brute force attack.
The severity of CVE-2015-6524 is high, with a severity value of 7.5.
CVE-2015-6524 affects Apache ActiveMQ versions 5.0.0 to 5.10.0.
To fix CVE-2015-6524, upgrade to Apache ActiveMQ version 5.10.1 or newer.
Additional information about CVE-2015-6524 can be found at the following references: [Reference 1](http://activemq.apache.org/security-advisories.data/CVE-2014-3612-announcement.txt), [Reference 2](http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168094.html), [Reference 3](http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168651.html).