CVE-2013-1879 Description Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message." Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. `activemq-core` was moved to `activemq-client` in version 5.8 Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1879 https://issues.apache.org/jira/browse/AMQ-4397 https://exchange.xforce.ibmcloud.com/vulnerabilities/85586 Project Category n/a Tags data Date Disclosed 2013-07-18 Date Discovered 2013-02-19 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More
CVE-2013-1768 Description The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1768 http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0099.html Project Category n/a Tags data functional Date Disclosed 2013-07-11 Date Discovered 2013-02-19 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More
CVE-2013-0239 Description Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. Workaround: A potential workaround is to not use a WS-SecurityPolicy that uses a plaintext `UsernameToken`. Documentation regarding this can be found at the link below: http://docs.oasis-open.org/ws-sx/security-policy/examples/ws-sp-usecases-examples.html#_Toc274723235 Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0239 https://cxf.apache.org/cve-2013-0239.html Project Category n/a Tags configuration functional Date Disclosed…
Read More
CVE-2012-5887 Description The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue or investigating other forms of authentication. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5887 http://tools.cisco.com/security/center/viewAlert.x?alertId=27343 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3439 Project Category n/a Tags functional Date Disclosed 2012-11-17 Date Discovered 2012-11-17 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us…
Read More
CVE-2012-5886 Description The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5886 http://tools.cisco.com/security/center/viewAlert.x?alertId=27343 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3439 Project Category n/a Tags functional Date Disclosed 2012-11-17 Date Discovered 2012-11-17 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More
CVE-2012-5885 Description The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue or investigating other forms of authentication. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5885 http://tools.cisco.com/security/center/viewAlert.x?alertId=27343 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3439 Project Category n/a Tags functional…
Read More
CVE-2012-5633 Description The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. If upgrading is not an option this vulnerability can be mitigated by removing URIMappingInterceptor from use or by utilizing WS-SecurityPolicy. Ref: http://cxf.apache.org/cve-2012-5633.html Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5633 http://cxf.apache.org/cve-2012-5633.html Project Category n/a Tags data configuration functional Date Disclosed 2013-03-12 Date Discovered 2012-10-24 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us…
Read More
CVE-2012-5575 Description Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack." Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5575 https://cxf.apache.org/cve-2012-5575.html https://bugzilla.redhat.com/show_bug.cgi?id=880443 Project Category n/a Tags data functional Date Disclosed 2013-08-19 Date Discovered 2012-10-24 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us…
Read More
CVE-2012-4534 Description org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-4534 http://tomcat.apache.org/security-6.html http://tomcat.apache.org/security-7.html https://bz.apache.org/bugzilla/show_bug.cgi?id=52858 Project Category n/a Tags data operational configuration Date Disclosed 2012-12-19 Date Discovered 2012-08-21 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More
CVE-2012-4431 Description org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-4431 https://rhn.redhat.com/errata/RHSA-2013-0268.html Project Category n/a Tags data functional Date Disclosed 2012-12-19 Date Discovered 2012-08-21 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More
