ZeroHour

CVE-2021-26117

CVSS 3.1
7.5 high
EPSS
11%p96
Published
()
Modified
Description

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

Vendors
apachenetappdebianoracle
Products
activemq, artemis, oncommand workflow automation, debian linux, communications element manager, communications session report manager, communications session route manager, flexcube private banking
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.