First published: Mon Mar 14 2016(Updated: )
Apache ActiveMQ could allow a remote attacker to hijack the clicking action of the victim, caused by the failure to set the X-Frame-Options header in HTTP responses by the Administrative Web console. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Directory Suite VA | <=8.0.1-8.0.1.19 | |
Apache ActiveMQ | =5.0.0 | |
Apache ActiveMQ | =5.1.0 | |
Apache ActiveMQ | =5.2.0 | |
Apache ActiveMQ | =5.3.0 | |
Apache ActiveMQ | =5.3.1 | |
Apache ActiveMQ | =5.3.2 | |
Apache ActiveMQ | =5.4.0 | |
Apache ActiveMQ | =5.4.1 | |
Apache ActiveMQ | =5.4.2 | |
Apache ActiveMQ | =5.4.3 | |
Apache ActiveMQ | =5.5.0 | |
Apache ActiveMQ | =5.5.1 | |
Apache ActiveMQ | =5.6.0 | |
Apache ActiveMQ | =5.7.0 | |
Apache ActiveMQ | =5.8.0 | |
Apache ActiveMQ | =5.9.0 | |
Apache ActiveMQ | =5.9.1 | |
Apache ActiveMQ | =5.10.0 | |
Apache ActiveMQ | =5.10.1 | |
Apache ActiveMQ | =5.10.2 | |
Apache ActiveMQ | =5.11.0 | |
Apache ActiveMQ | =5.11.1 | |
Apache ActiveMQ | =5.11.2 | |
Apache ActiveMQ | =5.12.0 | |
Apache ActiveMQ | =5.12.1 | |
Apache ActiveMQ | =5.12.2 | |
Apache ActiveMQ | =5.13.0 | |
redhat/activemq | <5.13.2 | 5.13.2 |
maven/org.apache.activemq:activemq-client | >=5.0.0<=5.13.1 | 5.13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2016-0734.
CVE-2016-0734 has a severity rating of medium.
CVE-2016-0734 affects Apache ActiveMQ versions 5.0.0 to 5.13.1.
An attacker can exploit CVE-2016-0734 by hijacking the clicking action of a victim through a malicious website.
Yes, a fix is available for CVE-2016-0734 in Apache ActiveMQ version 5.13.2.