CVE-2016-3094: Apache Qpid Broker-J
Medium severity, CVSS 5.9. EPSS: 7.8% chance of exploitation in the next 30 days.
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
Affected products
- Apache Qpid Broker-J: up to and including 6.0.2
Published 2016-06-01. Last modified 2026-06-17.