Resource management error in ActiveMQ - CVE-2011-4905
Published: January 5, 2012 / Updated: August 11, 2020
Vulnerability identifier: #VU44417
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4905
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
Affected software
ActiveMQ
IBM Cloud Application Performance Management (APM)
IBM Engineering Requirements Management DOORS Next
IBM Cloud Application Performance Management (APM)
IBM Engineering Requirements Management DOORS Next
How to mitigate CVE-2011-4905
Install update from vendor's website.
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
External References
- http://openwall.com/lists/oss-security/2011/12/25/2
- http://openwall.com/lists/oss-security/2011/12/25/6
- http://secunia.com/advisories/47112
- http://svn.apache.org/viewvc?view=revision&revision=1209700
- http://svn.apache.org/viewvc?view=revision&revision=1211844
- http://www.securityfocus.com/bid/50904
- https://issues.apache.org/jira/browse/AMQ-3294