Apache Qpid Java Authentication Bypass Vulnerability (CVE-2016-4432)
Apache Qpid Java Authentication Bypass Vulnerability (CVE-2016-4432)
Release date:
Updated on:
Affected Systems:
Apache Group Qpid Java <6.0.3
Apache Group Qpid Java
Description:
CVE (CAN) ID: CVE-2016-4432
Apache Qpid Java is the message Proxy Middleware. Write in Java and use AMQP to store, route, and forward messages.
Apache Qpid versions earlier than Java 6.0.3, AMQP 0-8, 0-9, 0-91, 0-10 connection processing has a security vulnerability. Remote attackers can exploit this vulnerability to bypass authentication for illegal operations.
<* Source: Apache
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://svn.apache.org/viewvc? View = revision & revision = 1743161
Https://svn.apache.org/viewvc? View = revision & revision = 1743393
Https://issues.apache.org/jira/browse/QPID-7257
This article permanently updates the link address: