It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
2019-08-01T14:15:10.940
2024-11-21T02:36:58.990
Modified
CVSSv3.1: 2.7 (LOW)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | activemq | < 5.14.5 | Yes |
Application | apache | activemq | < 5.15.5 | Yes |
Application | redhat | jboss_a-mq | 6.2.1 | Yes |
Application | redhat | jboss_a-mq | 6.3 | Yes |
Application | redhat | jboss_fuse | 6.3 | Yes |