CVE-2012-6551
Publication date 21 April 2013
Last updated 24 July 2024
Ubuntu priority
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
Status
Package | Ubuntu Release | Status |
---|---|---|
activemq | ||
14.04 LTS trusty | Not in release | |
Notes
References
Other references
- https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282
- https://issues.apache.org/jira/browse/AMQ-4124
- https://fisheye6.atlassian.com/changelog/activemq?cs=1404998
- http://activemq.apache.org/activemq-580-release.html
- http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.html
- https://www.cve.org/CVERecord?id=CVE-2012-6551