Hide Forgot
It was found that A-MQ's jolokia API does not have token or referrer checks, and could possibly allow a cross-site request forgery (CSRF) attack. An attacker could use this vulnerability to run application code with the same permissions as an authenticated user.
Acknowledgements: Red Hat would like to thank Naftali Rosenbaum of Comsec Consulting for reporting this issue.