Vulnerability Details CVE-2020-1941
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.044
EPSS Ranking 88.4%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-1941
-
cpe:2.3:a:apache:activemq:5.0.0
-
cpe:2.3:a:apache:activemq:5.1.0
-
cpe:2.3:a:apache:activemq:5.10.0
-
cpe:2.3:a:apache:activemq:5.10.1
-
cpe:2.3:a:apache:activemq:5.10.2
-
cpe:2.3:a:apache:activemq:5.11.0
-
cpe:2.3:a:apache:activemq:5.11.1
-
cpe:2.3:a:apache:activemq:5.11.2
-
cpe:2.3:a:apache:activemq:5.11.3
-
cpe:2.3:a:apache:activemq:5.12.0
-
cpe:2.3:a:apache:activemq:5.12.1
-
cpe:2.3:a:apache:activemq:5.12.2
-
cpe:2.3:a:apache:activemq:5.12.3
-
cpe:2.3:a:apache:activemq:5.13.0
-
cpe:2.3:a:apache:activemq:5.13.1
-
cpe:2.3:a:apache:activemq:5.13.2
-
cpe:2.3:a:apache:activemq:5.13.3
-
cpe:2.3:a:apache:activemq:5.13.4
-
cpe:2.3:a:apache:activemq:5.13.5
-
cpe:2.3:a:apache:activemq:5.14.0
-
cpe:2.3:a:apache:activemq:5.14.1
-
cpe:2.3:a:apache:activemq:5.14.2
-
cpe:2.3:a:apache:activemq:5.14.3
-
cpe:2.3:a:apache:activemq:5.14.4
-
cpe:2.3:a:apache:activemq:5.14.5
-
cpe:2.3:a:apache:activemq:5.15.0
-
cpe:2.3:a:apache:activemq:5.15.1
-
cpe:2.3:a:apache:activemq:5.15.10
-
cpe:2.3:a:apache:activemq:5.15.11
-
cpe:2.3:a:apache:activemq:5.15.2
-
cpe:2.3:a:apache:activemq:5.15.3
-
cpe:2.3:a:apache:activemq:5.15.4
-
cpe:2.3:a:apache:activemq:5.15.5
-
cpe:2.3:a:apache:activemq:5.15.6
-
cpe:2.3:a:apache:activemq:5.15.7
-
cpe:2.3:a:apache:activemq:5.15.8
-
cpe:2.3:a:apache:activemq:5.15.9
-
cpe:2.3:a:apache:activemq:5.2.0
-
cpe:2.3:a:apache:activemq:5.3.0
-
cpe:2.3:a:apache:activemq:5.3.1
-
cpe:2.3:a:apache:activemq:5.3.2
-
cpe:2.3:a:apache:activemq:5.4.0
-
cpe:2.3:a:apache:activemq:5.4.1
-
cpe:2.3:a:apache:activemq:5.4.2
-
cpe:2.3:a:apache:activemq:5.4.3
-
cpe:2.3:a:apache:activemq:5.5.0
-
cpe:2.3:a:apache:activemq:5.5.1
-
cpe:2.3:a:apache:activemq:5.6.0
-
cpe:2.3:a:apache:activemq:5.7.0
-
cpe:2.3:a:apache:activemq:5.8.0
-
cpe:2.3:a:apache:activemq:5.9.0
-
cpe:2.3:a:apache:activemq:5.9.1
-
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0
-
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0.0.0
-
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.1
-
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2
-
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.1
-
cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.2
-
cpe:2.3:a:oracle:communications_element_manager:8.1.1
-
cpe:2.3:a:oracle:communications_element_manager:8.2.0
-
cpe:2.3:a:oracle:communications_element_manager:8.2.1
-
cpe:2.3:a:oracle:communications_session_report_manager:8.1.1
-
cpe:2.3:a:oracle:communications_session_report_manager:8.2.0
-
cpe:2.3:a:oracle:communications_session_report_manager:8.2.1
-
cpe:2.3:a:oracle:communications_session_route_manager:8.1.1
-
cpe:2.3:a:oracle:communications_session_route_manager:8.2.0
-
cpe:2.3:a:oracle:communications_session_route_manager:8.2.1
-
cpe:2.3:a:oracle:enterprise_repository:11.1.1.7.0
-
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0
-
cpe:2.3:a:oracle:flexcube_private_banking:12.1.0