VulnerabilityModified
CVE-2014-3579
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
CRITICAL 9.8EPSS 4.59%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.59% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- apache/activemq apollo
- Source
- secalert@redhat.com
References
- http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txtVendor Advisory
- http://seclists.org/oss-sec/2015/q1/428Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72508Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100721Issue Tracking, Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/APLO-366Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
- http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txtVendor Advisory
- http://seclists.org/oss-sec/2015/q1/428Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72508Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100721Issue Tracking, Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/APLO-366Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.