<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache ActiveMQ Classic</title>
  <link>https://cvedaily.com/pages/tags/apache-activemq.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-activemq.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache ActiveMQ Classic</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-49270 – Exposure of Sensitive Information Through Metadata vulnerability in Apache Activ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49270</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49270</strong></p>
  <p>Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.  Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destin…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-1230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49157 – Incorrect Default Permissions vulnerability in Apache ActiveMQ.

This issue affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49157</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49157</strong></p>
  <p>Incorrect Default Permissions vulnerability in Apache ActiveMQ.  This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.  The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.  Users are recommended to up…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46605 – Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46605</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46605</strong></p>
  <p>Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.  This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.  Users are recommende…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45505 – Improper Input Validation, Improper Control of Generation of Code ('Code Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45505</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45505</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45505</strong></p>
  <p>Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.   Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197.   Original description from CVE-2026-34197.  Apache ActiveMQ exposes…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45505">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42588 – Improper Input Validation, Improper Control of Generation of Code ('Code Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42588</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42588</strong></p>
  <p>Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.  Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetw…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42253 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42253</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42253</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.  The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servl…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40914 – A vulnerability exists in Apache Artemis whereby an application using the STOMP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40914</guid>
    <pubDate>Thu, 28 May 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40914</strong></p>
  <p>A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. A user could successfully send a message to an address or consume a message f…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41044 – Improper Input Validation, Improper Control of Generation of Code ('Code Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41044</guid>
    <pubDate>Fri, 24 Apr 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41044</strong></p>
  <p>Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All.  An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM transport to load a remote Spring XML applicati…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41043 – Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41043</guid>
    <pubDate>Fri, 24 Apr 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41043</strong></p>
  <p>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.  An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.  This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 b…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40466 – Improper Input Validation, Improper Control of Generation of Code ('Code Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40466</guid>
    <pubDate>Fri, 24 Apr 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40466</strong></p>
  <p>Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.    An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia if the activemq-http module is on t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39304 – Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39304</guid>
    <pubDate>Fri, 10 Apr 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39304</strong></p>
  <p>Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.  ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.  Note: TLS versions before TLS…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40046 – Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40046</guid>
    <pubDate>Thu, 09 Apr 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40046</strong></p>
  <p>Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.  The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions.   This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34197 – Improper Input Validation, Improper Control of Generation of Code ('Code Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34197</guid>
    <pubDate>Tue, 07 Apr 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34197</strong></p>
  <p>Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.  Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String)…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33227 – Improper validation and restriction of a classpath path name vulnerability in 

...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33227</guid>
    <pubDate>Tue, 07 Apr 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33227</strong></p>
  <p>Improper validation and restriction of a classpath path name vulnerability in    Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.    In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenat…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32642 – Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache Active...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32642</guid>
    <pubDate>Tue, 24 Mar 2026 08:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32642</strong></p>
  <p>Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27446 – Missing Authentication for Critical Function (CWE-306) vulnerability in Apache A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27446</guid>
    <pubDate>Wed, 04 Mar 2026 09:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27446</strong></p>
  <p>Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66168 – WARNING:

Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66168</guid>
    <pubDate>Wed, 04 Mar 2026 09:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66168</strong></p>
  <p>WARNING:  Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.  See the  following for more details:  https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt   https://www.cve.org/CVERecord?id=CVE-2026-40046     Original Report:  Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54539 – A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54539</guid>
    <pubDate>Thu, 16 Oct 2025 09:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54539</strong></p>
  <p>A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client.  This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization logic present in the client to craft responses that may lead to arbitrary code execution on the cli…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-15046 – A client-side remote code execution vulnerability exists in Hanwha Techwin Smart...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-15046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-15046</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-15046</strong></p>
  <p>A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port 8161). An attacker can exploit this flaw through a Cross-Origin Resource Sharing (CORS) bypass combined with JavaScript-triggered file uploads to the web server…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-15046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27533 – Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.

D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27533</guid>
    <pubDate>Wed, 07 May 2025 09:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27533</strong></p>
  <p>Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.  During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-29953 – Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29953</guid>
    <pubDate>Fri, 18 Apr 2025 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-29953</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.  This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious responses that may eventually cause arbitrary code execution on the client. Version 2.1.0 introduced a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27391 – Insertion of Sensitive Information into Log File vulnerability in Apache ActiveM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27391</guid>
    <pubDate>Wed, 09 Apr 2025 15:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27391</strong></p>
  <p>Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled.  This issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users.  Users ar…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27427 – A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the create...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27427</guid>
    <pubDate>Tue, 01 Apr 2025 08:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27427</strong></p>
  <p>A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message wit…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50780 – Apache ActiveMQ Artemis allows access to diagnostic information and controls thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50780</guid>
    <pubDate>Mon, 14 Oct 2024 16:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50780</strong></p>
  <p>Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32114 – In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32114</guid>
    <pubDate>Thu, 02 May 2024 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32114</strong></p>
  <p>In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the broker (using Jolokia JMX REST API) and/or produce/consume messages or purge/delete destinations (using the Message REST A…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-35278 – In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35278</guid>
    <pubDate>Tue, 23 Aug 2022 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-35278</strong></p>
  <p>In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23913 – In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partiall...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23913</guid>
    <pubDate>Fri, 04 Feb 2022 23:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23913</strong></p>
  <p>In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13947 – An instance of a cross-site scripting vulnerability was identified to be present...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13947</guid>
    <pubDate>Mon, 08 Feb 2021 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13947</strong></p>
  <p>An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26118 – While investigating ARTEMIS-2964 it was found that the creation of advisory mess...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26118</guid>
    <pubDate>Wed, 27 Jan 2021 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26118</strong></p>
  <p>While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26117 – The optional ActiveMQ LDAP login module can be configured to use anonymous acces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26117</guid>
    <pubDate>Wed, 27 Jan 2021 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26117</strong></p>
  <p>The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13920 – Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI regis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13920</guid>
    <pubDate>Thu, 10 Sep 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13920</strong></p>
  <p>Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercep…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11998 – A regression has been introduced in the commit preventing JMX re-bind. By passin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11998</guid>
    <pubDate>Thu, 10 Sep 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11998</strong></p>
  <p>A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13932 – In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet whic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13932</guid>
    <pubDate>Mon, 20 Jul 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13932</strong></p>
  <p>In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1941 – In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1941</guid>
    <pubDate>Thu, 14 May 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1941</strong></p>
  <p>In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-7559 – It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7559</guid>
    <pubDate>Thu, 01 Aug 2019 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-7559</strong></p>
  <p>It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-0222 – In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0222</guid>
    <pubDate>Thu, 28 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-0222</strong></p>
  <p>In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-8006 – An instance of a cross-site scripting vulnerability was identified to be present...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-8006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-8006</guid>
    <pubDate>Wed, 10 Oct 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-8006</strong></p>
  <p>An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11775 – TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11775</guid>
    <pubDate>Mon, 10 Sep 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11775</strong></p>
  <p>TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6810 – In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6810</guid>
    <pubDate>Wed, 10 Jan 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6810</strong></p>
  <p>In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-3600 – XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3600</guid>
    <pubDate>Fri, 27 Oct 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-3600</strong></p>
  <p>XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-3579 – XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3579</guid>
    <pubDate>Fri, 27 Oct 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-3579</strong></p>
  <p>XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4978 – The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4978</guid>
    <pubDate>Tue, 27 Sep 2016 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4978</strong></p>
  <p>The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-0782 – The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0782</guid>
    <pubDate>Fri, 05 Aug 2016 15:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-0782</strong></p>
  <p>The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3088 – The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3088</guid>
    <pubDate>Wed, 01 Jun 2016 20:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3088</strong></p>
  <p>The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-0734 – The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0734</guid>
    <pubDate>Thu, 07 Apr 2016 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-0734</strong></p>
  <p>The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-5254 – Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be seri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5254</guid>
    <pubDate>Fri, 08 Jan 2016 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-5254</strong></p>
  <p>Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-6524 – The LDAPLoginModule implementation in the Java Authentication and Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6524</guid>
    <pubDate>Mon, 24 Aug 2015 14:59:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-6524</strong></p>
  <p>The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3612 – The LDAPLoginModule implementation in the Java Authentication and Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3612</guid>
    <pubDate>Mon, 24 Aug 2015 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3612</strong></p>
  <p>The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wild…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1830 – Directory traversal vulnerability in the fileserver upload/download functionalit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1830</guid>
    <pubDate>Wed, 19 Aug 2015 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1830</strong></p>
  <p>Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3576 – The processControlCommand function in broker/TransportConnection.java in Apache ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3576</guid>
    <pubDate>Fri, 14 Aug 2015 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3576</strong></p>
  <p>The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8110 – Multiple cross-site scripting (XSS) vulnerabilities in the web based administrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8110</guid>
    <pubDate>Thu, 12 Feb 2015 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8110</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-1880 – Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1880</guid>
    <pubDate>Wed, 05 Feb 2014 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-1880</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-1879 – Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1879</guid>
    <pubDate>Sat, 20 Jul 2013 03:37:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-1879</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-3060 – The web console in Apache ActiveMQ before 5.8.0 does not require authentication,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3060</guid>
    <pubDate>Sun, 21 Apr 2013 21:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-3060</strong></p>
  <p>The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-6551 – The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6551</guid>
    <pubDate>Sun, 21 Apr 2013 21:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-6551</strong></p>
  <p>The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-6092 – Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6092</guid>
    <pubDate>Sun, 21 Apr 2013 21:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-6092</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js.  NOTE: AMQ-4124 is covered by…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5784 – Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5784</guid>
    <pubDate>Sun, 04 Nov 2012 22:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5784</strong></p>
  <p>Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL s…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4905 – Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4905</guid>
    <pubDate>Thu, 05 Jan 2012 16:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4905</strong></p>
  <p>Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1587 – The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1587</guid>
    <pubDate>Wed, 28 Apr 2010 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1587</strong></p>
  <p>The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1244 – Cross-site request forgery (CSRF) vulnerability in createDestination.action in A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1244</guid>
    <pubDate>Mon, 05 Apr 2010 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1244</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2010-0684 – Cross-site scripting (XSS) vulnerability in createDestination.action in Apache A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0684</guid>
    <pubDate>Mon, 05 Apr 2010 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2010-0684</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0684">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
