Description
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
http://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txt
http://seclists.org/oss-sec/2015/q1/427
http://secunia.com/advisories/62649
http://www.securityfocus.com/bid/72511
https://exchange.xforce.ibmcloud.com/vulnerabilities/100724
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Related Vulnerabilities
CVE-2013-6397 Vulnerability in maven package org.apache.solr:solr-velocity
CVE-2022-38180 Vulnerability in maven package io.ktor:ktor-client-core
CVE-2019-1003065 Vulnerability in maven package org.jenkins-ci.plugins:cloudshare-docker
CVE-2013-2133 Vulnerability in maven package org.wildfly:wildfly-ejb3
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat:tomcat-el-api