CVEs (72)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache DebianOracle4Activemq Communications Diameter Signaling RouterDebian Linux+1 moreJun 17, 2026 Sep 10, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method...Show more |
2Apache Oracle7Activemq Communications Diameter Signaling RouterCommunications Element Manager+4 moreJun 17, 2026 Sep 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open t...Show more |
2Apache Oracle7Activemq Communications Diameter Signaling RouterCommunications Element Manager+4 moreJun 17, 2026 May 14, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. |
2Apache Redhat3Activemq Jboss A MqJboss FuseNov 21, 2024 Aug 1, 2019 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service...Show more |
5Apache DebianNetapp+2 more10Activemq Debian LinuxDrill+7 moreJun 17, 2026 May 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information c...Show more |
3Apache OracleXstream3Activemq Endeca Information Discovery StudioXstreamMay 23, 2025 May 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarsh...Show more |
4Apache DebianEclipse+1 more7Activemq Debian LinuxDrill+4 moreJun 17, 2026 Apr 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandle...Show more |
4Apache DebianNetapp+1 more8Activemq Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Mar 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive. |
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is...Show more |
2Apache Oracle3Activemq Enterprise RepositoryFlexcube Private BankingNov 21, 2024 Sep 10, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ serv...Show more |
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text. |
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output va...Show more |
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages. |
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain...Show more |
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request. |
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page th...Show more |
3Apache FedoraprojectRedhat3Activemq FedoraOpenshiftMay 6, 2026 Jan 8, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMess...Show more |
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credenti...Show more |
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password an...Show more |
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories vi...Show more |