#VU40671 Credentials management in Fedora and ActiveMQ - CVE-2015-6524
Published: August 24, 2015 / Updated: August 9, 2020
Fedora
ActiveMQ
Fedoraproject
Apache Foundation
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.