CVE-2021-26117
—CVSS 3.1
7.5 high
EPSS
11%p96
Published
()
Modified
Description
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
- Vendors
- apachenetappdebianoracle
- Products
- activemq, artemis, oncommand workflow automation, debian linux, communications element manager, communications session report manager, communications session route manager, flexcube private banking
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.