CVE-2010-1587 is a source code disclosure vulnerability affecting Apache ActiveMQ versions 5.x before 5.3.2 and 5.4.x before 5.4.0. Attackers can exploit a flaw in the Jetty ResourceHandler to read JSP source code from specific administrative pages by including "//" in the URI. This vulnerability has a CVSS score of 5.0, indicating a medium severity, and allows for information disclosure (C:P) without requiring authentication (Au:N) or complex attack conditions (AC:L). The EPSS score of 0.75383 suggests a higher-than-average likelihood of exploitation, further supported by its high FAUCET Risk Score of 99/100. While not on the KEV catalog, exploit modules are available in Metasploit and ExploitDB, confirming the existence of public exploit code. Despite the availability of exploits, there is no recorded community discussion or media coverage, which is typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.0CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:* | ||
5.1.0CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:* | ||
5.2.0CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:* | ||
5.3.0CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:* | ||
5.3.1CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.