CVE-2016-8653: Medium severity red hat jboss a-mq vulnerability
Published Nov 25, 2016
·Updated
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
Affected Software
2 affected components
redhat JBoss A-MQ=6.0.0
redhat Jboss Fuse=6.0.0
Event History
Nov 25, 2016
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
05:39 AM
Affected Software
Aug 1, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8653?
CVE-2016-8653 has a severity of medium, primarily due to its potential for denial of service attacks.
2
How do I fix CVE-2016-8653?
To fix CVE-2016-8653, upgrade to a patched version of Red Hat JBoss Fuse or Red Hat A-MQ that addresses this vulnerability.
3
What software versions are affected by CVE-2016-8653?
CVE-2016-8653 affects Red Hat JBoss Fuse and Red Hat A-MQ, specifically version 6.0.0.
4
What is the impact of CVE-2016-8653?
The impact of CVE-2016-8653 can lead to denial of service due to the deserialization of credentials in the JMX endpoint.
5
Is there a workaround for CVE-2016-8653?
Currently, the recommended action for CVE-2016-8653 is to apply the security update, as there are no reliable workarounds.