CVE-2015-7559: Input Validation
Apache ActiveMQ client is vulnerable to a denial of service, caused by a remote shutdown command in the ActiveMQConnection class. By sending a specific command, a remote authenticated attacker could exploit this vulnerability to cause the application to stop responding.
Other sources
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2015-7559?
CVE-2015-7559 is a vulnerability in the Apache ActiveMQ client that can be exploited by a remote authenticated attacker to cause a denial of service.
What is the severity of CVE-2015-7559?
The severity of CVE-2015-7559 is medium, with a severity value of 6.5.
How does CVE-2015-7559 affect Apache ActiveMQ?
CVE-2015-7559 affects Apache ActiveMQ versions up to and including 5.14.5, and versions between 5.15.0 and 5.15.5. It allows a remote authenticated attacker to execute a remote shutdown command, causing the application to stop responding.
Are Redhat Jboss A-mq and Redhat Jboss Fuse affected by CVE-2015-7559?
Yes, Redhat Jboss A-mq version 6.2.1 and Redhat Jboss Fuse version 6.3 are affected by CVE-2015-7559.
Is IBM Security Directory Suite VA affected by CVE-2015-7559?
IBM Security Directory Suite VA version up to and including 8.0.1.19 is affected by CVE-2015-7559.