QID 730055
Date Published: 2021-04-22
QID 730055: Apache ActiveMQ LDAP-Authentication Vulnerability (CVE-2021-26117)
Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client.
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server.
Affected Versions:
ActiveMQ prior to versions 5.16.1 and 5.15.14
QID Detection Logic (Unauthenticated):
This QID tries to get the Apache ActiveMQ versions from admin/index.jsp pages if the target allows unauthenticated access to the admin directory.
Attacker could configure ActiveMQ LDAP-Authentication module to login anonymously
Solution
Customer are advised to update to Apache ActiveMQ 5.16.1 and 5.15.14 or later versions to remediate this vulnerability.
Vendor References
CVEs related to QID 730055
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache ActiveMQ |
|