Qpid Broker J
Vendor:
First CVE: Jun 1, 2016 · Active for 10 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Qpid Broker J over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2016
10 years ago
Most Recent CVE
Mar 6, 2019
2,699 days ago
CVE Severity & Scoring
Qpid Broker J8 CVEs
25%
50%
25%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15702CRITICAL In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can | Dec 1, 2017 | 9.8 | 33 | NO | NO |
CVE-2016-4432CRITICAL The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via ve | Jun 1, 2016 | 9.1 | 33 | NO | NO |
CVE-2016-8741HIGH The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM- | May 15, 2017 | 7.5 | 28 | NO | NO |
CVE-2017-15701HIGH In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker cou | Dec 1, 2017 | 7.5 | 27 | NO | NO |
CVE-2019-0200HIGH A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instance | Mar 6, 2019 | 7.5 | 26 | NO | NO |
CVE-2018-8030HIGH A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than al | Jun 20, 2018 | 7.5 | 26 | NO | NO |
CVE-2016-3094MEDIUM PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker term | Jun 1, 2016 | 5.9 | 25 | NO | NO |
CVE-2018-1298MEDIUM A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN o | Feb 9, 2018 | 5.9 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Qpid Broker J
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.1.0 | 1 | 7.5 | 3.8% | 0 | 0 |
| 7.0.0 | 1 | 5.9 | 2.3% | 0 | 0 |
| 6.1.0 | 1 | 7.5 | 6.3% | 0 | 0 |
| 6.0.5 | 1 | 7.5 | 6.3% | 0 | 0 |
| 6.0.4 | 1 | 7.5 | 6.3% | 0 | 0 |
| 6.0.3 | 1 | 7.5 | 6.3% | 0 | 0 |
| 6.0.2 | 1 | 7.5 | 6.3% | 0 | 0 |
| 6.0.1 | 1 | 7.5 | 6.3% | 0 | 0 |