Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-6092
HistoryApr 21, 2013 - 12:00 a.m.

CVE-2012-6092

2013-04-2100:00:00
ubuntu.com
ubuntu.com
20

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.005

Percentile

76.8%

Multiple cross-site scripting (XSS) vulnerabilities in the web demos in
Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web
script or HTML via (1) the refresh parameter to
PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data
Publisher), or vectors involving (2) debug logs or (3) subscribe messages
in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.

Notes

Author Note
mdeslaur example code not shipped in Ubuntu/Debian

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.005

Percentile

76.8%