Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-1587

76
FAUCET Score

CVE-2010-1587 is a source code disclosure vulnerability affecting Apache ActiveMQ versions 5.x before 5.3.2 and 5.4.x before 5.4.0. Attackers can exploit a flaw in the Jetty ResourceHandler to read JSP source code from specific administrative pages by including "//" in the URI. This vulnerability has a CVSS score of 5.0, indicating a medium severity, and allows for information disclosure (C:P) without requiring authentication (Au:N) or complex attack conditions (AC:L). The EPSS score of 0.75383 suggests a higher-than-average likelihood of exploitation, further supported by its high FAUCET Risk Score of 99/100. While not on the KEV catalog, exploit modules are available in Metasploit and ExploitDB, confirming the existence of public exploit code. Despite the availability of exploits, there is no recorded community discussion or media coverage, which is typical for a large percentage of CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
5.0.0CPE matchmatch criteria
cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:*
5.1.0CPE matchmatch criteria
cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:*
5.2.0CPE matchmatch criteria
cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:*
5.3.0CPE matchmatch criteria
cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:*
5.3.1CPE matchmatch criteria
cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
78.02%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-33868 · Apr 22, 2010
This CVE's current EPSS score of 0.7802 is in the 100th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-web-consoleFixed in: 5.3.2

Vendor Advisories (2)

mavenGHSA-v2c9-9m8v-8jjmmedium

Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler

May 14, 2022
redhatCVE-2010-1587Low

ActiveMQ JSP source disclosure

Apr 20, 2010

References

archives.neohapsis.com / archives/fulldisclosure/2010-04/0278.html
secunia.com / advisories/39567
Vendor Advisory
issues.apache.org / activemq/browse/AMQ-2700
Patch
osvdb.org / 64020
Exploit
securityfocus.com / archive/1/510896/100/0/threaded
securityfocus.com / bid/39636
vupen.com / english/advisories/2010/0979
Vendor Advisory