« Volver al listado

CVE-2014-3579

Estado: ModificadaCrítica (9.8)—

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-3579",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-27T19:29:00.190",
  "references": [
    {
      "url": "http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/oss-sec/2015/q1/428",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/72508",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/100721",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.apache.org/jira/browse/APLO-366",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/oss-sec/2015/q1/428",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/72508",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/100721",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.apache.org/jira/browse/APLO-366",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de XEE (XML External Entity) en Apache ActiveMQ Apollo, en versiones 1.x anteriores a la 1.7.1, permite que consumidores remotos provoquen un impacto sin especificar mediante vectores relacionados con un selector basado en XPath al eliminar de la cola los mensajes XML."
    }
  ],
  "lastModified": "2026-06-17T00:08:33.160",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "030F086F-7C86-41FF-BDB6-A36453908712"
            },
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC11B011-212F-486A-BD39-AC8993B2D8E2"
            },
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C49D82C5-4768-4D5F-AD38-6857DA048026"
            },
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43C60E86-D89F-44BE-B65B-3212A13F1CAB"
            },
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6094353E-7E72-4105-985F-A21EC058D94D"
            },
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BBEDA99-5F98-46ED-9DAC-9FB122A1295E"
            },
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "784992B5-7726-486A-ACF7-8B6D3D569FCD"
            },
            {
              "criteria": "cpe:2.3:a:apache:activemq_apollo:1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B050D873-08F0-45CF-8D0F-BA4A58AD97F9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}