The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests. [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6551
This issue has been addressed in following products: Fuse MQ Enterprise 7.1.0 Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html