Back to search
CVE-2014-3612
Published: Aug 24, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
72513
vdb-entry
x_refsource_BID
[oss-security] 20150205 [ANNOUNCE] CVE-2014-3600, CVE-2014-3612 and CVE-2014-8110 - Apache ActiveMQ vulnerabilities
mailing-list
x_refsource_MLIST
RHSA-2015:0137
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0138
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now