← Vulnerability feed

Vulnerability record · CVE-2016-8741 · published 15 May 2017

CVE-2016-8741: Apache qpid broker-j information exposure vulnerability

Apache · Qpid Broker J

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.

7.5 CVSS 3.1 High EPSS 6.3% · top 6.6% CWE-200 · Information exposure
7.5CVSS 3.1 base score, v2 5.0
6.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8741 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-15702Apache qpid broker-j vulnerabilityIn Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an …EPSS 6.2%9.1CVE-2016-4432Apache qpid broker-j improper authentication vulnerabilityThe AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons…EPSS 8.1%7.5CVE-2026-68073Apache qpid broker-j vulnerabilityA pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects …EPSS 0.77%7.5CVE-2026-68060Apache qpid broker-j allocation without limits vulnerabilityA pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issu…EPSS 0.77%7.5CVE-2026-68074Apache qpid broker-j allocation without limits vulnerabilityA pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue aff…EPSS 0.77%7.5CVE-2019-0200Apache qpid broker-j vulnerabilityA Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attack…EPSS 3.8%7.5CVE-2018-8030Apache qpid broker-j improper input validation vulnerabilityA Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish mes…EPSS 3.9%7.5CVE-2017-15701Apache qpid broker-j uncontrolled resource consumption vulnerabilityIn Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remo…EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2016-8741), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.