VulnerabilityModified
CVE-2014-3600
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
CRITICAL 9.8EPSS 9.71%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.71% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- apache/activemq
- Source
- secalert@redhat.com
References
- http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txtVendor Advisory
- http://seclists.org/oss-sec/2015/q1/427Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72510Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100722Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/AMQ-5333Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
- http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txtVendor Advisory
- http://seclists.org/oss-sec/2015/q1/427Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72510Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100722Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/AMQ-5333Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.