PT-2019-7207 · Apache+2 · Apache Activemq+2

Chess Hazlett

·

Published

2019-08-01

·

Updated

2024-07-23

·

CVE-2015-7559

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ client versions prior to 5.15.5
Description A remote shutdown command in the ActiveMQConnection class was exposed, allowing an attacker logged into a compromised broker to achieve denial of service on a connected client.
Recommendations For Apache ActiveMQ client versions prior to 5.15.5, update to version 5.15.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the ActiveMQConnection class to minimize the risk of exploitation.

Exploit

Fix

DoS

Missing Authentication

RCE

Weakness Enumeration

Related Identifiers

CVE-2015-7559
DLA-913-1
GHSA-JVPP-HXJJ-5CCC
USN-6910-1

Affected Products

Apache Activemq
Linuxmint
Ubuntu