CVE-2014-8110

MEDIUM

Description

Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

References

http://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txt

http://seclists.org/oss-sec/2015/q1/427

http://secunia.com/advisories/62649

http://www.securityfocus.com/bid/72511

https://exchange.xforce.ibmcloud.com/vulnerabilities/100724

https://lists.apache.org/thread.html/[email protected]%3Ccommits.activemq.apache.org%3E

Details

Source: MITRE

Published: 2015-02-12

Updated: 2019-03-27

Type: CWE-79

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM