CVE Vulnerabilities

CVE-2016-0734

Published: Apr 07, 2016 | Modified: Apr 12, 2025
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
3.1 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

Affected Software

NameVendorStart VersionEnd Version
ActivemqApache5.0.0 (including)5.0.0 (including)
ActivemqApache5.1.0 (including)5.1.0 (including)
ActivemqApache5.2.0 (including)5.2.0 (including)
ActivemqApache5.3.0 (including)5.3.0 (including)
ActivemqApache5.3.1 (including)5.3.1 (including)
ActivemqApache5.3.2 (including)5.3.2 (including)
ActivemqApache5.4.0 (including)5.4.0 (including)
ActivemqApache5.4.1 (including)5.4.1 (including)
ActivemqApache5.4.2 (including)5.4.2 (including)
ActivemqApache5.4.3 (including)5.4.3 (including)
ActivemqApache5.5.0 (including)5.5.0 (including)
ActivemqApache5.5.1 (including)5.5.1 (including)
ActivemqApache5.6.0 (including)5.6.0 (including)
ActivemqApache5.7.0 (including)5.7.0 (including)
ActivemqApache5.8.0 (including)5.8.0 (including)
ActivemqApache5.9.0 (including)5.9.0 (including)
ActivemqApache5.9.1 (including)5.9.1 (including)
ActivemqApache5.10.0 (including)5.10.0 (including)
ActivemqApache5.10.1 (including)5.10.1 (including)
ActivemqApache5.10.2 (including)5.10.2 (including)
ActivemqApache5.11.0 (including)5.11.0 (including)
ActivemqApache5.11.1 (including)5.11.1 (including)
ActivemqApache5.11.2 (including)5.11.2 (including)
ActivemqApache5.12.0 (including)5.12.0 (including)
ActivemqApache5.12.1 (including)5.12.1 (including)
ActivemqApache5.12.2 (including)5.12.2 (including)
ActivemqApache5.13.0 (including)5.13.0 (including)
Red Hat JBoss A-MQ 6.2RedHat*
Red Hat JBoss Fuse 6.2RedHat*

References