apache activemq CVE-2014-3612 is a vulnerability in Apache ActiveMQ
Published on August 24, 2015

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2014-3612

Want to know whenever a new CVE is published for Apache ActiveMQ? stack.watch will email you.

 

Exploit Probability

EPSS
0.71%
Percentile
71.80%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.