vulnerability

Apache ActiveMQ: CVE-2016-0782: ActiveMQ Web Console - Cross-Site Scripting

Severity
3
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
2016-08-05
Added
2024-01-09
Modified
2025-01-20

Description

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

Solution

apache-activemq-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.