LiveActive security incident?Get immediate response
CVE Record

CVE-2018-1298: A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authenticati...

A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL mechanism is used. The vulnerability allows unauthenticated attacker to crash the broker instance. AMQP 1.0 and HTTP connections are not affected. An authentication of incoming AMQP connections in Apache Qpid Broker-J is performed by special entities called "Authentication Providers". Each Authentication Provider can support several SASL mechanisms which are offered to the connecting clients as part of SASL negotiation process. The client chooses the most appropriate SASL mechanism for authentication. Authentication Providers of following types supports PLAIN SASL mechanism: Plain, PlainPasswordFile, SimpleLDAP, Base64MD5PasswordFile, MD5, SCRAM-SHA-256, SCRAM-SHA-1. XOAUTH2 SASL mechanism is supported by Authentication Providers of type OAuth2. If an AMQP port is configured with any of these Authentication Providers, the Broker may be vulnerable.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Apache Qpid Broker-J 7.0.0 can be crashed by unauthenticated connection attempts when certain older AMQP protocols use PLAIN or XOAUTH2 SASL authentication. This is an availability issue: exposed message brokers could be knocked offline, disrupting applications that depend on queued messaging. AMQP 1.0 and HTTP connections are not affected.

Executive priority

Prioritize remediation where Qpid Broker-J 7.0.0 supports critical business workflows or accepts network connections from untrusted zones. The business risk is outage of messaging-dependent applications. Environments not using the affected version, affected protocols, or affected SASL mechanisms have materially lower urgency.

Technical view

The flaw affects authentication handling for AMQP 0-8, 0-9, 0-91, and 0-10 when an AMQP port offers PLAIN or XOAUTH2 via listed Authentication Provider types. A malicious unauthenticated client can crash the broker instance. Sources identify Apache Qpid Broker-J 7.0.0 only; no CVSS vector or CWE is provided.

Likely exposure

Likely exposure is limited to organizations running Apache Qpid Broker-J 7.0.0 with AMQP ports using affected SASL mechanisms. Internet-facing brokers, shared internal messaging hubs, and systems lacking service supervision face higher operational impact. AMQP 1.0 and HTTP-only use is out of scope per the source.

Exploitation context

The bundle does not cite CISA KEV listing, public active exploitation, or exploit tooling. The documented attacker position is unauthenticated access to an affected AMQP port. Impact is broker process availability, not data theft or privilege escalation, based on the supplied description.

Researcher notes

The source details affected SASL mechanisms and provider types but does not include root cause, patch version, CVSS, CWE, or proof-of-concept details. Treat scope narrowly: Apache Qpid Broker-J 7.0.0, specified pre-1.0 AMQP protocols, and PLAIN or XOAUTH2-capable authentication providers.

Mitigation direction

  • Check Apache Qpid guidance for the fixed version or vendor-recommended mitigation.
  • Identify and upgrade any Apache Qpid Broker-J 7.0.0 instances.
  • Restrict network access to AMQP ports to trusted clients only.
  • Review AMQP port authentication providers for PLAIN or XOAUTH2 exposure.
  • Ensure broker service monitoring and restart policies are in place.

Validation and detection

  • Inventory Apache Qpid Broker-J versions across production and non-production environments.
  • List enabled AMQP ports and their supported protocol versions.
  • Review Authentication Provider types bound to each AMQP port.
  • Confirm whether PLAIN or XOAUTH2 SASL mechanisms are offered.
  • Verify AMQP 1.0 and HTTP-only endpoints are not misclassified as affected.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-1298 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Apache Software FoundationApache Qpid Broker-J7.0.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.