CVE-2015-7559

MEDIUM4.9EPSS 0.08%

Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ

Published: 8/1/2019Modified: 2/16/2024
Also known as:GHSA-jvpp-hxjj-5cccDEBIAN-CVE-2015-7559

Description

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.9CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

References (6)