CVE-2017-15701
CVE-2017-15701
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 4.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
01 Dec 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.
Affected products
Apache Software Foundation · Apache Qpid Broker-JWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →