XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Activemq | Apache | 5.0.0 (including) | 5.0.0 (including) |
| Activemq | Apache | 5.1.0 (including) | 5.1.0 (including) |
| Activemq | Apache | 5.2.0 (including) | 5.2.0 (including) |
| Activemq | Apache | 5.3.0 (including) | 5.3.0 (including) |
| Activemq | Apache | 5.3.1 (including) | 5.3.1 (including) |
| Activemq | Apache | 5.3.2 (including) | 5.3.2 (including) |
| Activemq | Apache | 5.4.0 (including) | 5.4.0 (including) |
| Activemq | Apache | 5.4.1 (including) | 5.4.1 (including) |
| Activemq | Apache | 5.4.2 (including) | 5.4.2 (including) |
| Activemq | Apache | 5.4.3 (including) | 5.4.3 (including) |
| Activemq | Apache | 5.5.0 (including) | 5.5.0 (including) |
| Activemq | Apache | 5.5.1 (including) | 5.5.1 (including) |
| Activemq | Apache | 5.6.0 (including) | 5.6.0 (including) |
| Activemq | Apache | 5.7.0 (including) | 5.7.0 (including) |
| Activemq | Apache | 5.8.0 (including) | 5.8.0 (including) |
| Activemq | Apache | 5.9.0 (including) | 5.9.0 (including) |
| Activemq | Apache | 5.9.1 (including) | 5.9.1 (including) |
| Activemq | Apache | 5.10.0 (including) | 5.10.0 (including) |
| Fuse ESB Enterprise 7.1.0 | RedHat | * | |
| Fuse Management Console 7.1.0 | RedHat | * | |
| Fuse MQ Enterprise 7.1.0 | RedHat | * | |
| Red Hat JBoss A-MQ 6.1 | RedHat | * | |
| Red Hat JBoss Fuse 6.1 | RedHat | * | |
| Activemq | Ubuntu | precise | * |
| Activemq | Ubuntu | trusty | * |
| Activemq | Ubuntu | upstream | * |