Back

MEDIUM

activemq: Unauthenticated access to web console

Published Apr 21, 2013

Description

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.

Affected products

Remediation

Red Hat statement

Fuse ESB Enterprise 7.1.0, Fuse MQ Enterprise 7.1.1, JBoss Fuse 6.0.0 and JBoss A-MQ 6.0.0 all contain the Apache ActiveMQ web console, but it is not deployed by default. The documentation for deploying the web console covers the configuration needed to ensure authentication is enabled, therefore these products are not affected by this flaw. In a future update to these products, the web console will be configured so that authentication is automatically enabled if the web console is deployed, eliminating the need to manually configure it. A future update may address this flaw in Fuse Message Broker 5.5.1.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 21, 2013
Updated Aug 6, 2024
Reserved Apr 15, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Nov 2, 2012
GHSA-P358-58JJ-HP65