CVE-2014-3612
Improper Authentication in Apache WSS4J
EPSS 7.4%
描述
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
如何修補 CVE-2014-3612
要修補 CVE-2014-3612,請將受影響套件升級到下列已修補版本。
- Debian/activemq—升級至 5.6.0+dfsg1-4 或更新版本
- —升級至 5.10.1 或更新版本
- —升級至 5.10.1 或更新版本
CVE-2014-3612 正在被利用嗎?
中等 — EPSS 為 7.4%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 5.6.0+dfsg1-4
- >= 5.0.0, < 5.10.1
- >= 5.0.0, < 5.10.1