PT-2020-13787 · Apache · Apache Tomee

Frans Henskens

·

Published

2020-12-17

·

Updated

2022-02-09

·

CVE-2020-13931

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache TomEE versions 1.0.0 through 1.7.5 Apache TomEE versions 7.0.0-M1 through 7.0.8 Apache TomEE versions 7.1.0 through 7.1.3 Apache TomEE versions 8.0.0-M1 through 8.0.3
Description The issue arises when Apache TomEE is configured to use the embedded ActiveMQ broker with a misconfigured broker setup, resulting in the opening of a JMX port on TCP port 1099 without authentication. This is an edge case that was not covered by a previous fix.
Recommendations For Apache TomEE versions 1.0.0 through 1.7.5, consider disabling the JMX management interface until a proper fix is applied. For Apache TomEE versions 7.0.0-M1 through 7.0.8, restrict access to the JMX port on TCP port 1099 to minimize the risk of exploitation. For Apache TomEE versions 7.1.0 through 7.1.3, avoid using the embedded ActiveMQ broker with a misconfigured setup until the issue is resolved. For Apache TomEE versions 8.0.0-M1 through 8.0.3, as a temporary workaround, consider disabling the embedded ActiveMQ broker until a patch is available.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13931
GHSA-MP28-RQ7G-QX62

Affected Products

Apache Tomee