PT-2016-5956 · Apache · Apache Qpid Java

Alex Rudyy

·

Publicado

2016-06-01

·

Atualizado

2022-12-07

·

CVE-2016-4432

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Qpid Java versions prior to 6.0.3
Description The issue concerns the AMQP 0-8, 0-9, 0-91, and 0-10 connection handling, which might allow remote attackers to bypass authentication. This could enable attackers to perform actions via vectors related to connection state logging.
Recommendations For versions prior to 6.0.3, update to version 6.0.3 or later to resolve the issue.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4432
GHSA-Q66C-H853-GQW2

Produtos afetados

Apache Qpid Java