CVE-2016-3094

medium
Published 2016-06-01 · Modified 2024-02-16
CVSS v3
5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
4.3
VIR risk
5.9

Description

Improper Input Validation in org.apache.qpid:qpid-broker

Predictions

Exploit likelihood
69%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://svn.apache.org/viewvc?view=revision&revision=1744403

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://issues.apache.org/jira/browse/QPID-7271

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://qpid.apache.org/releases/qpid-java-6.0.3/release-notes.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://mail-archives.apache.org/mod_mbox/qpid-users/201605.mbox/%3C5748641A.2050701%40gmail.com%3E

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.qpid:qpid-broker<6.0.36.0.3

Application impact

VendorProductVersionsFixed
apache apacheqpid_broker-j{"endIncluding":"6.0.2"}

References

CWEs

CWE-20 CWE-287

Verify integrity in audit chain (admin only). AS-IS.