CVE-2014-8110
MEDIUM severity · CVSS 4.3 · Cross-site scripting (XSS)
4.3CVSS MEDIUM
Summary
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)7%
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txtAdvisory
- http://seclists.org/oss-sec/2015/q1/427
- http://secunia.com/advisories/62649
- http://www.securityfocus.com/bid/72511
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100724
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E