CVE-2014-3579
9.8
CRITICAL · CVSS 3.0 · EPSS 4.6% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.59% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-10-27 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | activemq apollo |
References
- http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt
- http://seclists.org/oss-sec/2015/q1/428
- http://www.securityfocus.com/bid/72508
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100721
- https://issues.apache.org/jira/browse/APLO-366
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
- http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt
- http://seclists.org/oss-sec/2015/q1/428
- http://www.securityfocus.com/bid/72508
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100721
- https://issues.apache.org/jira/browse/APLO-366
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
→ the Explorer · watch your stack · NVD