VulnerabilityModified
CVE-2016-3094
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught…
MEDIUM 5.9EPSS 7.83%
Does this matter?
Lower severity and a low EPSS score (7.83%). Track it; it rarely justifies an emergency change on its own.
Description
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 7.83% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-287
- Affected
- apache/qpid broker-j
- Source
- secalert@redhat.com
References
- http://mail-archives.apache.org/mod_mbox/qpid-users/201605.mbox/%3C5748641A.2050701%40gmail.com%3EVendor Advisory
- http://packetstormsecurity.com/files/137215/Apache-Qpid-Java-Broker-6.0.2-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
- http://qpid.apache.org/releases/qpid-java-6.0.3/release-notes.htmlRelease Notes
- http://www.securityfocus.com/archive/1/538507/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035982Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/QPID-7271Vendor Advisory
- https://svn.apache.org/viewvc?view=revision&revision=1744403Release Notes
- http://mail-archives.apache.org/mod_mbox/qpid-users/201605.mbox/%3C5748641A.2050701%40gmail.com%3EVendor Advisory
- http://packetstormsecurity.com/files/137215/Apache-Qpid-Java-Broker-6.0.2-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
- http://qpid.apache.org/releases/qpid-java-6.0.3/release-notes.htmlRelease Notes
- http://www.securityfocus.com/archive/1/538507/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035982Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/QPID-7271Vendor Advisory
- https://svn.apache.org/viewvc?view=revision&revision=1744403Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.