Secunia Security Advisory - A vulnerability has been discovered in Apache ActiveMQ, which can be exploited by malicious people to disclose potentially sensitive information.
ed156c3f274885b7eda139ab125b1b5b53f4a2a3e2d0fea79c3695620bdd23de
----------------------------------------------------------------------
Secunia CSI
+ Microsoft SCCM
-----------------------
= Extensive Patch Management
http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/
----------------------------------------------------------------------
TITLE:
Apache ActiveMQ Source Code Disclosure Vulnerability
SECUNIA ADVISORY ID:
SA39567
VERIFY ADVISORY:
http://secunia.com/advisories/39567/
DESCRIPTION:
A vulnerability has been discovered in Apache ActiveMQ, which can be
exploited by malicious people to disclose potentially sensitive
information.
The vulnerability is caused due to an error when handling certain
requests, which can be exploited to disclose the source code of e.g.
".jsp" files via specially crafted requests.
The vulnerability is confirmed in ActiveMQ version 5.3.1.
SOLUTION:
Follow the workaround. Also fixed in the newest ActiveMQ 5.4
snapshots.
https://issues.apache.org/activemq/browse/AMQ-2700
PROVIDED AND/OR DISCOVERED BY:
Veerendra G.G, SecPod Technologies
ORIGINAL ADVISORY:
SecPod Technologies:
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/att-0278/SECPOD_ActiveMQ.txt
ActiveMQ bug #2700:
https://issues.apache.org/activemq/browse/AMQ-2700
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------