6.4

CVE-2013-3060

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.

Data is provided by the National Vulnerability Database (NVD)
ApacheActivemq Version <= 5.7.0
ApacheActivemq Version4.0
ApacheActivemq Version4.0 Updatem4
ApacheActivemq Version4.0 Updaterc2
ApacheActivemq Version4.0.1
ApacheActivemq Version4.0.2
ApacheActivemq Version4.1.0
ApacheActivemq Version4.1.1
ApacheActivemq Version5.0.0
ApacheActivemq Version5.1.0
ApacheActivemq Version5.2.0
ApacheActivemq Version5.3.0
ApacheActivemq Version5.3.1
ApacheActivemq Version5.3.2
ApacheActivemq Version5.4.0
ApacheActivemq Version5.4.1
ApacheActivemq Version5.4.2
ApacheActivemq Version5.5.0
ApacheActivemq Version5.5.1
ApacheActivemq Version5.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.02% 0.752
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.