Skip to main content

Vendor/product archive

apache / qpid_broker-j CVEs

Beta · best-effort

8 CVEs tagged to apache / qpid_broker-j2 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2019-0200

Published Mar 6, 2019

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instanc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8030

Published Jun 20, 2018

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1298

Published Feb 9, 2018

A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15702

Published Dec 1, 2017

In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15701

Published Dec 1, 2017

In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8741

Published May 15, 2017

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4432

Published Jun 1, 2016

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via v…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3094

Published Jun 1, 2016

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker ter…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1