CVE-2016-4432

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
01/06/2016
Last modified:
12/04/2025

Description

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:qpid_broker-j:*:*:*:*:*:*:*:* 6.0.3 (excluding)