---
title: "CVE-2012-6092\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-6092?format=md
keywords: index, follow
---

# CVE-2012-6092

Publication date 21 April 2013

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple cross-site scripting (XSS) vulnerabilities in the web demos in
Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web
script or HTML via (1) the refresh parameter to
PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data
Publisher), or vectors involving (2) debug logs or (3) subscribe messages
in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-6092?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| activemq | 15.10 wily | Not affected |
| 15.04 vivid | Ignored end of life |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Ignored end of life |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Ignored end of life |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

example code not shipped in Ubuntu/Debian

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6092)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-6092)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-6092)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-6092)

### Other references

* <https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282>
* <https://issues.apache.org/jira/browse/AMQ-4115>
* <https://fisheye6.atlassian.com/changelog/activemq?cs=1399577>
* <http://activemq.apache.org/activemq-580-release.html>
* <https://www.cve.org/CVERecord?id=CVE-2012-6092>
