← Back

CVE-2015-6524

nvd nist
Published: Aug 24, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.

Affected (20)

1 product
Fedora
1 product
Activemq
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 22
Version 23
Configuration B
18 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 5.0.0
Version 5.1.0
Version 5.10.0
Version 5.2.0
Version 5.3.0
Version 5.3.1
Version 5.3.2
Version 5.4.0
Version 5.4.1
Version 5.4.2
Version 5.4.3
Version 5.5.0
Version 5.5.1
Version 5.6.0
Version 5.7.0
Version 5.8.0
Version 5.9.0
Version 5.9.1

Related CWEs

Timeline

No history available yet.