QID 730055

Date Published: 2021-04-22

QID 730055: Apache ActiveMQ LDAP-Authentication Vulnerability (CVE-2021-26117)

Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client.

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server.

Affected Versions:
ActiveMQ prior to versions 5.16.1 and 5.15.14

QID Detection Logic (Unauthenticated):
This QID tries to get the Apache ActiveMQ versions from admin/index.jsp pages if the target allows unauthenticated access to the admin directory.

Attacker could configure ActiveMQ LDAP-Authentication module to login anonymously

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customer are advised to update to Apache ActiveMQ 5.16.1 and 5.15.14 or later versions to remediate this vulnerability.

    CVEs related to QID 730055

    Software Advisories
    Advisory ID Software Component Link
    Apache ActiveMQ URL Logo activemq.apache.org/security-advisories.data/CVE-2021-26117-announcement.txt