Cross-site scripting in ActiveMQ - CVE-2016-6810

 

Cross-site scripting in ActiveMQ - CVE-2016-6810

Published: January 10, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31366
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2016-6810
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.


Affected software

ActiveMQ

How to mitigate CVE-2016-6810

Install update from vendor's website.

ActiveMQ - update to 5.14.2

External References

Related Security Bulletins