CVE-2016-3094: Apache Qpid Broker-J

Medium severity, CVSS 5.9. EPSS: 7.8% chance of exploitation in the next 30 days.

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

Affected products

  • Apache Qpid Broker-J: up to and including 6.0.2

Published 2016-06-01. Last modified 2026-06-17.