← Back

CVE-2020-13931

nvd nist
Published: Dec 18, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.

Affected (8)

Products: Apache: Tomee
1 product
Tomee
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.0.0 to 1.7.5
From 7.0.0 to 7.0.8
From 7.1.0 to 7.1.3
From 8.0.0 to 8.0.3
Version 7.0.0 m1
Version 7.0.0 m2
Version 7.0.0 m3
Version 8.0.0 m1

Timeline

No history available yet.