Fedora Account System
Red Hat Associate
Red Hat Customer
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp. http://www.securityfocus.com/archive/1/archive/1/510896/100/0/threaded https://issues.apache.org/activemq/browse/AMQ-2700 http://www.vupen.com/english/advisories/2010/0979
Statement: Not vulnerable. Apache ActiveMQ is not shipped with any supported Red Hat products.