CVE-2017-15701: High severity apache qpid broker-j vulnerability
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15701?
CVE-2017-15701 is classified as a medium-severity vulnerability.
How do I fix CVE-2017-15701?
To fix CVE-2017-15701, upgrade Apache Qpid Broker-J to a version later than 6.1.4.
What types of attacks can exploit CVE-2017-15701?
CVE-2017-15701 can be exploited by remote unauthenticated attackers to exhaust the memory of the broker.
Which versions of Apache Qpid Broker-J are affected by CVE-2017-15701?
Apache Qpid Broker-J versions 6.1.0 through 6.1.4 are affected by CVE-2017-15701.
What happens if CVE-2017-15701 is exploited successfully?
If CVE-2017-15701 is successfully exploited, it may lead to the broker terminating due to memory exhaustion.