CVE-2014-3600

X

ML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.4.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.4.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.7.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.9.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.9.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:5.10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:08

Type Values Removed Values Added
References () http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txt - Vendor Advisory () http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txt - Vendor Advisory
References () http://seclists.org/oss-sec/2015/q1/427 - Mailing List, Third Party Advisory () http://seclists.org/oss-sec/2015/q1/427 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/72510 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/72510 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/100722 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/100722 - Third Party Advisory, VDB Entry
References () https://issues.apache.org/jira/browse/AMQ-5333 - Issue Tracking, Third Party Advisory () https://issues.apache.org/jira/browse/AMQ-5333 - Issue Tracking, Third Party Advisory
References () https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E - () https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E -

Information

Published : 2017-10-27 19:29

Updated : 2025-04-20 01:37


NVD link : CVE-2014-3600

Mitre link : CVE-2014-3600

CVE.ORG link : CVE-2014-3600


JSON object : View

Products Affected
CWE
CWE-611

Improper Restriction of XML External Entity Reference