PT-2017-5877 · Apache · Apache Activemq Apollo

Published

2017-10-27

·

Updated

2022-05-14

·

CVE-2014-3579

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache ActiveMQ Apollo versions 1.0 through 1.7.0
Description: The issue is related to an XML external entity (XXE) vulnerability. It affects remote consumers and involves vectors related to an XPath based selector when dequeuing XML messages.
Recommendations: For Apache ActiveMQ Apollo versions 1.0 through 1.7.0, update to version 1.7.1 or later to resolve the issue.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3579
GHSA-WMHW-HPWH-44PG

Affected Products

Apache Activemq Apollo