CVE-2015-6524
Improper Input Validation in Apache ActiveMQ
EPSS 8.5%
描述
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
如何修補 CVE-2015-6524
要修補 CVE-2015-6524,請將受影響套件升級到下列已修補版本。
- Debian/activemq—升級至 5.6.0+dfsg1-4 或更新版本
- Maven/org.apache.activemq:activemq-broker—升級至 5.10.2 或更新版本
- —升級至 5.10.2 或更新版本
CVE-2015-6524 正在被利用嗎?
中等 — EPSS 為 8.5%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 5.6.0+dfsg1-4
- >= 5.0.0, < 5.10.2
- >= 5.0.0, < 5.10.2