« Volver al listado

CVE-2012-4446

Estado: ModificadaMedia (6.8)—

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4446",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-03-14T03:10:22.530",
  "references": [
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0561.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0562.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/52516",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=851355",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.apache.org/jira/browse/QPID-4631",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0561.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0562.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/52516",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=851355",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.apache.org/jira/browse/QPID-4631",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request."
    },
    {
      "lang": "es",
      "value": "La configuración por defecto de Apache Qpid v0.20 y anteriores, cuando el atributo federation_tag está activo, acepta conexiones AMQP sin comprobar el ID del usuario que lo manda, lo que permite a atacantes remotos evitar la autenticación y tener otras sin especificar a través de peticiones AMQP."
    }
  ],
  "lastModified": "2026-06-16T23:45:06.907",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EFF35CD-0D3D-4B29-8E7A-9C39D7358A3A",
              "versionEndIncluding": "0.20"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71A147B7-2E6B-4E7A-8C68-BEDFCACD57AD"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "760A5796-9BB5-45A3-AB0E-D3639D487A76"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D441FDC2-CA4E-43C5-A3DD-3715641E59A4"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79CB1E30-BDD9-451E-A366-EE19C2E00AF0"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8690F211-CE64-4799-87C5-F2AEDB0500EA"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "469FC441-523B-4C78-9B2D-46B8CCE8811E"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB64A222-C258-44BF-A83D-CFE1204F8009"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C584B299-0BB9-4B4F-B0BC-11DE222F1F17"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D74323FF-612A-48EE-A03E-D49CAD828101"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21261207-0DF5-460A-9F9B-F8CADB78DAF7"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5A6F2E8-325C-4071-9862-8242B730B147"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "578FB3FD-EA55-4A39-94D4-F4194C0F2BB3"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C67B5857-3CD8-445A-B60D-C0285BB60A07"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2949A7DC-2955-4770-94CE-5AB9EEC3B1DB"
            },
            {
              "criteria": "cpe:2.3:a:apache:qpid:0.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B227D078-8298-4594-8F96-F2976F189B6A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}