PT-2020-13781 · Apache+2 · Apache Activemq+2
Published
2020-09-10
·
Updated
2024-07-23
·
CVE-2020-13920
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ versions prior to 5.15.12
Description
The issue allows an attacker to connect to the JMX RMI registry without authentication and rebind the
jmxrmi entry. By creating a proxy server, an attacker can intercept user credentials.Recommendations
For versions prior to 5.15.12, upgrade to Apache ActiveMQ 5.15.12 to resolve the issue.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Activemq
Linuxmint
Ubuntu