Lucene search

K
cve[email protected]CVE-2011-3620
HistoryMay 03, 2012 - 11:55 p.m.

CVE-2011-3620

2012-05-0323:55:01
CWE-287
web.nvd.nist.gov
20
cve-2011-3620
apache qpid
cluster
remote attackers
credential verification
messaging functionality
job functionality

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.0%

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.

Affected configurations

NVD
Node
apacheqpidMatch0.12
CPENameOperatorVersion
apache:qpidapache qpideq0.12

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.0%