ZeroHour

CVE-2021-26118

CVSS 3.1
7.5 high
EPSS
4%p90
Published
()
Modified
Description

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

Vendors
apachenetapp
Products
artemis, oncommand workflow automation
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.