Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2014-3600

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote…

Technology

Apache ActiveMQ

CVSS Score

9.8 / 10.0

Affected Versions

5.0.0; 5.1.0; 5.2.0; 5.3.0

Upstream Fix

See upstream advisory

Published

October 27, 2017

OSSeva Coverage

Fixed upstream

Description

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

Is your Apache ActiveMQ deployment affected?

If you're running 5.0.0; 5.1.0; 5.2.0; 5.3.0, you need this patch. Book a discovery call to get covered.