CVE-2016-3094

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/06/2016
Last modified:
12/04/2025

Description

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:qpid_broker-j:*:*:*:*:*:*:*:* 6.0.2 (including)