Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2014-3600
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote…
Technology
Apache ActiveMQ
CVSS Score
9.8 / 10.0
Affected Versions
5.0.0; 5.1.0; 5.2.0; 5.3.0
Upstream Fix
See upstream advisory
Published
October 27, 2017
OSSeva Coverage
Fixed upstream
Description
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Is your Apache ActiveMQ deployment affected?
If you're running 5.0.0; 5.1.0; 5.2.0; 5.3.0, you need this patch. Book a discovery call to get covered.