PT-2020-5485 · Apache · Apache Activemq

Published

2020-09-10

·

Updated

2024-03-06

·

CVE-2020-11998

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.15.13
Description The issue is related to a regression introduced in a commit that prevents JMX re-bind, allowing a remote client to create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs if there is no security manager. This could enable a rogue remote client to make the Java application execute arbitrary code.
Recommendations Upgrade to Apache ActiveMQ 5.15.13 to resolve the issue. As a temporary workaround, consider restricting access to the RMIConnectorServer to minimize the risk of exploitation. Avoid passing an empty environment map to RMIConnectorServer, and ensure that the map contains the necessary authentication credentials.

Fix

Code Injection

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2021-00781
BIT-ACTIVEMQ-2020-11998
CVE-2020-11998
GHSA-WQFH-9M4G-7X6X

Affected Products

Apache Activemq