Vulnerability Details CVE-2015-0203
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.112
EPSS Ranking 93.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2015-0203
-
cpe:2.3:a:apache:qpid:0.10
-
cpe:2.3:a:apache:qpid:0.11
-
cpe:2.3:a:apache:qpid:0.12
-
cpe:2.3:a:apache:qpid:0.13
-
cpe:2.3:a:apache:qpid:0.14
-
cpe:2.3:a:apache:qpid:0.15
-
cpe:2.3:a:apache:qpid:0.16
-
cpe:2.3:a:apache:qpid:0.17
-
cpe:2.3:a:apache:qpid:0.18
-
cpe:2.3:a:apache:qpid:0.19
-
cpe:2.3:a:apache:qpid:0.20
-
cpe:2.3:a:apache:qpid:0.22
-
cpe:2.3:a:apache:qpid:0.27.0
-
cpe:2.3:a:apache:qpid:0.30
-
cpe:2.3:a:apache:qpid:0.5
-
cpe:2.3:a:apache:qpid:0.6
-
cpe:2.3:a:apache:qpid:0.7
-
cpe:2.3:a:apache:qpid:0.8
-
cpe:2.3:a:apache:qpid:0.9