PT-2016-1672 · Apache · Apache Activemq

Christopher Shannon

·

Publicado

2016-04-07

·

Atualizado

2022-05-14

·

CVE-2016-0734

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions 5.x before 5.13.2
Description The issue is related to the web-based administration console in Apache ActiveMQ, which does not send an X-Frame-Options HTTP header. This makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a FRAME or IFRAME element. The exploitation of this issue may allow a remote attacker to place malicious elements on a page and force a user to activate them using specially formed web pages.
Recommendations For Apache ActiveMQ versions 5.x before 5.13.2, update to version 5.13.2 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00998
CVE-2016-0734
GHSA-W525-W93J-RXGM

Produtos afetados

Apache Activemq