CVE-2016-3094: Input Validation
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3094?
CVE-2016-3094 is classified as a high severity vulnerability due to its potential to cause denial of service by terminating the broker via crafted authentication attempts.
How do I fix CVE-2016-3094?
To fix CVE-2016-3094, upgrade your Apache Qpid Java Broker to version 6.0.3 or later.
What causes the vulnerability in CVE-2016-3094?
CVE-2016-3094 is caused by a flaw in PlainSaslServer.java when the broker allows plaintext passwords, allowing attackers to trigger uncaught exceptions.
Can CVE-2016-3094 be exploited remotely?
Yes, CVE-2016-3094 can be exploited remotely by attackers through crafted authentication attempts.
Is my Apache Qpid Broker-J vulnerable if it is running version 6.0.2 or earlier?
Yes, if you are running Apache Qpid Broker-J version 6.0.2 or earlier, you are vulnerable to CVE-2016-3094.