CVE-2015-6524: Input Validation
Apache ActiveMQ is vulnerable to a brute force attack, caused by an error in the LDAPLoginModule implementation. An attacker could exploit this vulnerability using the wildcard in usernames to obtain user credentials.
Other sources
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-6524?
CVE-2015-6524 is a vulnerability in Apache ActiveMQ that allows remote attackers to obtain credentials via a brute force attack.
What is the severity of CVE-2015-6524?
The severity of CVE-2015-6524 is high, with a severity value of 7.5.
Which software versions are affected by CVE-2015-6524?
CVE-2015-6524 affects Apache ActiveMQ versions 5.0.0 to 5.10.0.
How can I fix CVE-2015-6524?
To fix CVE-2015-6524, upgrade to Apache ActiveMQ version 5.10.1 or newer.
Where can I find more information about CVE-2015-6524?
Additional information about CVE-2015-6524 can be found at the following references: [Reference 1](http://activemq.apache.org/security-advisories.data/CVE-2014-3612-announcement.txt), [Reference 2](http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168094.html), [Reference 3](http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168651.html).