It was found that A-MQ's Hawtio console setting for the Access-Control-Allow-Origin header permits unrestricted sharing. An attacker could use this flaw to access sensitive information or perform other attacks.
Acknowledgements: Red Hat would like to thank Naftali Rosenbaum of Comsec Consulting for reporting this issue.
Statement: This flaw affects only the Red Hat AMQ Product, and does not impact Apache ActiveMQ.