Vulnerability record · CVE-2016-8741 · published 15 May 2017
CVE-2016-8741: Apache qpid broker-j information exposure vulnerability
Apache · Qpid Broker J
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.
Description
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://qpid.2158936.n2.nabble.com/CVE-2016-8741-Apache-Qpid-Broker-for-Java-Information-Leakage-td7657025.html | Vendor Advisory |
| http://www.securityfocus.com/bid/95136 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037537 | Broken LinkThird Party AdvisoryVDB Entry |
| https://issues.apache.org/jira/browse/QPID-7599 | Issue Tracking |
| http://qpid.2158936.n2.nabble.com/CVE-2016-8741-Apache-Qpid-Broker-for-Java-Information-Leakage-td7657025.html | Vendor Advisory |
| http://www.securityfocus.com/bid/95136 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1037537 | Broken LinkThird Party AdvisoryVDB Entry |
| https://issues.apache.org/jira/browse/QPID-7599 | Issue Tracking |
Track CVE-2016-8741 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8741), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.