Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 955908 - (CVE-2013-3060) CVE-2013-3060 activemq: Unauthenticated access to web console
CVE-2013-3060 activemq: Unauthenticated access to web console
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20121102,repo...
: Security
Depends On: 956950 956951
Blocks: 955433 958349
  Show dependency treegraph
 
Reported: 2013-04-24 00:23 EDT by Arun Babu Neelicattu
Modified: 2016-05-19 10:30 EDT (History)
13 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-09-09 16:46:52 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:1029 normal SHIPPED_LIVE Important: Fuse MQ Enterprise 7.1.0 update 2013-07-09 17:56:11 EDT
Red Hat Product Errata RHSA-2013:1221 normal SHIPPED_LIVE Important: Fuse Message Broker 5.5.1 security update 2013-09-09 16:55:25 EDT

  None (edit)
Description Arun Babu Neelicattu 2013-04-24 00:23:25 EDT
The web console in Apache ActiveMQ before 5.8.0 does not require authentication. Remote attackers could use this flaw to modify the state of the ActiveMQ environment, obtain sensitive information or cause a denial of service via HTTP requests.
Comment 1 David Jorm 2013-04-26 01:11:07 EDT
External References:

(none)
Comment 3 David Jorm 2013-04-26 01:26:15 EDT
Statement:

Fuse ESB Enterprise 7.1.0, Fuse MQ Enterprise 7.1.1, JBoss Fuse 6.0.0 and JBoss A-MQ 6.0.0 all contain the Apache ActiveMQ web console, but it is not deployed by default. The documentation for deploying the web console covers the configuration needed to ensure authentication is enabled, therefore these products are not affected by this flaw. In a future update to these products, the web console will be configured so that authentication is automatically enabled if the web console is deployed, eliminating the need to manually configure it.

A future update may address this flaw in Fuse Message Broker 5.5.1.
Comment 6 errata-xmlrpc 2013-07-09 13:57:58 EDT
This issue has been addressed in following products:

  Fuse MQ Enterprise 7.1.0

Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html
Comment 7 errata-xmlrpc 2013-09-09 12:57:06 EDT
This issue has been addressed in following products:

  Fuse Message Broker 5.5.1

Via RHSA-2013:1221 https://rhn.redhat.com/errata/RHSA-2013-1221.html

Note You need to log in before you can comment on or make changes to this bug.