CVE-2016-4432: Critical severity apache qpid broker-j vulnerability
Published Jun 1, 2016
·Updated
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.
Affected Software
1 affected component
Apache Qpid Broker-J<6.0.3
Remediation
Patch Available
Patch Available
Event History
Jun 1, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4432?
CVE-2016-4432 has a medium severity level due to its potential to allow remote attackers to bypass authentication.
2
How do I fix CVE-2016-4432?
To fix CVE-2016-4432, upgrade Apache Qpid Java to version 6.0.3 or higher.
3
What software is affected by CVE-2016-4432?
CVE-2016-4432 affects Apache Qpid Broker-J versions prior to 6.0.3.
4
What type of attack does CVE-2016-4432 facilitate?
CVE-2016-4432 facilitates authentication bypass attacks on affected systems.
5
Is CVE-2016-4432 present in newer versions of Apache Qpid?
No, CVE-2016-4432 is not present in Apache Qpid versions 6.0.3 and later.