Medium severity6.1NVD Advisory· Published Apr 7, 2016· Updated Jun 17, 2026
CVE-2016-0734
CVE-2016-0734
Description
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.activemq:activemq-clientMaven | >= 5.0.0, < 5.13.2 | 5.13.2 |
Affected products
28cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:*+ 26 more
- cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.10.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.13.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:5.9.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- activemq.apache.org/security-advisories.data/CVE-2016-0734-announcement.txtnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-w525-w93j-rxgmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-0734ghsaADVISORY
- www.openwall.com/lists/oss-security/2016/03/10/11nvdWEB
- access.redhat.com/errata/RHSA-2016:1424nvdWEB
- github.com/apache/activemq/commit/028a33ea7d73fabe6161defffdbfc85578328a68ghsaWEB
- github.com/apache/activemq/commit/24ad36778534c5ac888f880837075449169578adghsaWEB
- lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3EghsaWEB
- www.securityfocus.com/bid/84321nvd
- www.securitytracker.com/id/1035327nvd
- lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Envd
News mentions
0No linked articles in our index yet.