Red Hat AMQ Broker是美国红帽(Red Hat)公司的一个纯 Java 多协议消息代理。它建立在高效的异步核心之上,具有用于消息持久性的快速本机日志和用于高可用性的无共享状态复制选项。 AMQ Broker 存在访问控制错误漏洞,该漏洞源于对没有角色集的用户的访问限制不当。 远程特权用户可以绕过实施的安全限制并获得对管理控制台中的未授权访问。该漏洞允许远程用户获得对其他受限功能的未授权访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | AMQ Broker | Fixed in amq-7.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-24381 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25888 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25761 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-24298 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21208 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25231 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25304 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25302 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-37428 | 6.5 MEDIUM | PowerDNS Recursor 安全漏洞 |
| CVE-2021-3839 | DPDK 缓冲区错误漏洞 | |
| CVE-2021-3670 | Samba ldb 安全漏洞 | |
| CVE-2022-35115 | IceWarp WebClient SQL注入漏洞 | |
| CVE-2020-35509 | Red Hat Keycloak 信任管理问题漏洞 | |
| CVE-2021-3827 | Red Hat Keycloak 授权问题漏洞 | |
| CVE-2022-37111 | BlueCMS SQL注入漏洞 | |
| CVE-2022-37112 | BlueCMS SQL注入漏洞 | |
| CVE-2022-37113 | BlueCMS SQL注入漏洞 | |
| CVE-2022-37223 | jfinal cms SQL注入漏洞 | |
| CVE-2022-37199 | jfinal cms SQL注入漏洞 | |
| CVE-2022-36261 | taoCMS 路径遍历漏洞 |
Showing top 20 of 54 CVEs. View all on vendor page → →
No comments yet