Apache ActiveMQ XML external entity Injection Vulnerability (CVE-2014-3600)
Release date:
Updated on:
Affected Systems:
Apache Group ActiveMQ Apollo
Description:
Bugtraq id: 72510
CVE (CAN) ID: CVE-2014-3600
Apache ActiveMQ is a popular message transmission and integration mode provider.
Apache ActiveMQ 5.0.0-5.10.0 has the XML external entity injection vulnerability. Attackers can exploit this vulnerability to obtain sensitive information or cause DoS attacks.
<* Source: Georgi gesev
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://activemq.apache.org/apollo/
ActiveMQ installation in Linux
ACTIVEMQ server in Ubuntu
Spring + JMS + ActiveMQ + Tomcat Implement Message Service
Set ActiveMQ port and WEB port in Linux
This article permanently updates the link address: