CVE-2021-26117
Published on: 01/27/2021 12:00:00 AM UTC
Last Modified on: 12/07/2021 08:47:00 PM UTC
Certain versions of Activemq from Apache contain the following vulnerability:
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
- CVE-2021-26117 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Apache Software Foundation - Apache ActiveMQ version < 2.16.0
- Affected Vendor/Software:
Apache Software Foundation - Apache ActiveMQ version < 5.16.1
- Affected Vendor/Software:
Apache Software Foundation - Apache ActiveMQ version < 5.15.14
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apache | Activemq | All | All | All | All |
Application | Apache | Activemq | All | All | All | All |
Application | Apache | Activemq Artemis | All | All | All | All |
Application | Apache | Activemq Artemis | All | All | All | All |
Operating System | Debian | Debian Linux | 9.0 | All | All | All |
Operating System | Debian | Debian Linux | 9.0 | All | All | All |
Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
Application | Oracle | Communications Element Manager | All | All | All | All |
Application | Oracle | Communications Session Report Manager | All | All | All | All |
Application | Oracle | Communications Session Route Manager | All | All | All | All |
Application | Oracle | Flexcube Private Banking | 12.0.0 | All | All | All |
Application | Oracle | Flexcube Private Banking | 12.1.0 | All | All | All |
- cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*:
Discovery Credit
Apache ActiveMQ would like to thank Gregor Tudan
Social Mentions
Source | Title | Posted (UTC) |
---|