Lucene search

K
cve[email protected]CVE-2012-4446
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-4446

2022-10-0316:15:34
CWE-287
web.nvd.nist.gov
42
cve-2012-4446
apache qpid
amqp
authentication bypass
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.0%

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

Affected configurations

NVD
Node
apacheqpidRange0.20
OR
apacheqpidMatch0.5
OR
apacheqpidMatch0.6
OR
apacheqpidMatch0.7
OR
apacheqpidMatch0.8
OR
apacheqpidMatch0.9
OR
apacheqpidMatch0.10
OR
apacheqpidMatch0.11
OR
apacheqpidMatch0.12
OR
apacheqpidMatch0.13
OR
apacheqpidMatch0.14
OR
apacheqpidMatch0.15
OR
apacheqpidMatch0.16
OR
apacheqpidMatch0.17
OR
apacheqpidMatch0.18
OR
apacheqpidMatch0.19

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.0%