DNA View

CVE-2016-6810

Low
Low Medium High Critical
CVSS Score
Published: Jan 10, 2018
Last Modified: Nov 21, 2024

Vulnerability Description

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.

Known Affected Software

36 configuration(s) from 1 vendor(s)

activemq
Version:
5.4.2
CPE:
cpe:2.3:a:apache:activemq:5.4.2:*:*:*:*:*:*:*
activemq
Version:
5.12.2
CPE:
cpe:2.3:a:apache:activemq:5.12.2:*:*:*:*:*:*:*
activemq
Version:
5.13.4
CPE:
cpe:2.3:a:apache:activemq:5.13.4:*:*:*:*:*:*:*
activemq
Version:
5.14.0
CPE:
cpe:2.3:a:apache:activemq:5.14.0:*:*:*:*:*:*:*
activemq
Version:
5.11.3
CPE:
cpe:2.3:a:apache:activemq:5.11.3:*:*:*:*:*:*:*
activemq
Version:
5.3.0
CPE:
cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:*
activemq
Version:
5.11.0
CPE:
cpe:2.3:a:apache:activemq:5.11.0:*:*:*:*:*:*:*
activemq
Version:
5.4.3
CPE:
cpe:2.3:a:apache:activemq:5.4.3:*:*:*:*:*:*:*
activemq
Version:
5.0.0
CPE:
cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:*
activemq
Version:
5.10.1
CPE:
cpe:2.3:a:apache:activemq:5.10.1:*:*:*:*:*:*:*
activemq
Version:
5.3.2
CPE:
cpe:2.3:a:apache:activemq:5.3.2:*:*:*:*:*:*:*
activemq
Version:
5.9.0
CPE:
cpe:2.3:a:apache:activemq:5.9.0:*:*:*:*:*:*:*
activemq
Version:
5.8.0
CPE:
cpe:2.3:a:apache:activemq:5.8.0:*:*:*:*:*:*:*
activemq
Version:
5.10.0
CPE:
cpe:2.3:a:apache:activemq:5.10.0:*:*:*:*:*:*:*
activemq
Version:
5.12.1
CPE:
cpe:2.3:a:apache:activemq:5.12.1:*:*:*:*:*:*:*
activemq
Version:
5.4.1
CPE:
cpe:2.3:a:apache:activemq:5.4.1:*:*:*:*:*:*:*
activemq
Version:
5.2.0
CPE:
cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:*
activemq
Version:
5.12.0
CPE:
cpe:2.3:a:apache:activemq:5.12.0:*:*:*:*:*:*:*
activemq
Version:
5.3.1
CPE:
cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:*
activemq
Version:
5.13.1
CPE:
cpe:2.3:a:apache:activemq:5.13.1:*:*:*:*:*:*:*
activemq
Version:
5.7.0
CPE:
cpe:2.3:a:apache:activemq:5.7.0:*:*:*:*:*:*:*
activemq
Version:
5.12.3
CPE:
cpe:2.3:a:apache:activemq:5.12.3:*:*:*:*:*:*:*
activemq
Version:
5.10.2
CPE:
cpe:2.3:a:apache:activemq:5.10.2:*:*:*:*:*:*:*
activemq
Version:
5.9.1
CPE:
cpe:2.3:a:apache:activemq:5.9.1:*:*:*:*:*:*:*
activemq
Version:
5.13.2
CPE:
cpe:2.3:a:apache:activemq:5.13.2:*:*:*:*:*:*:*
activemq
Version:
5.1.0
CPE:
cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:*
activemq
Version:
5.13.5
CPE:
cpe:2.3:a:apache:activemq:5.13.5:*:*:*:*:*:*:*
activemq
Version:
5.13.3
CPE:
cpe:2.3:a:apache:activemq:5.13.3:*:*:*:*:*:*:*
activemq
Version:
5.13.0
CPE:
cpe:2.3:a:apache:activemq:5.13.0:*:*:*:*:*:*:*
activemq
Version:
5.5.1
CPE:
cpe:2.3:a:apache:activemq:5.5.1:*:*:*:*:*:*:*
activemq
Version:
5.5.0
CPE:
cpe:2.3:a:apache:activemq:5.5.0:*:*:*:*:*:*:*
activemq
Version:
5.11.2
CPE:
cpe:2.3:a:apache:activemq:5.11.2:*:*:*:*:*:*:*
activemq
Version:
5.11.1
CPE:
cpe:2.3:a:apache:activemq:5.11.1:*:*:*:*:*:*:*
activemq
Version:
5.4.0
CPE:
cpe:2.3:a:apache:activemq:5.4.0:*:*:*:*:*:*:*
activemq
Version:
5.6.0
CPE:
cpe:2.3:a:apache:activemq:5.6.0:*:*:*:*:*:*:*
activemq
Version:
5.14.1
CPE:
cpe:2.3:a:apache:activemq:5.14.1:*:*:*:*:*:*:*
This vulnerability affects 36 software configuration(s). Ensure you patch all affected systems.

Severity Details

out of 10.0
Low

Weakness Type (CWE)

CWE-79 Top 25 #1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Exploit Likelihood
High
Typical Severity
Medium
OWASP Top 10
A03:2021-Injection
Abstraction Level
Base

Key Information

Published Date
January 10, 2018