CVE-2016-0782: Apache ActiveMQ

Medium severity, CVSS 5.4. EPSS: 6.1% chance of exploitation in the next 30 days.

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.

Affected products

  • Apache ActiveMQ: version 5.1.0 only; version 5.2.0 only; version 5.3.0 only; version 5.3.1 only; version 5.3.2 only; version 5.4.0 only; …

Published 2016-08-05. Last modified 2026-06-17.