PT-2021-16958 · Apache+2 · Apache Activemq+3

Published

2021-01-27

·

Updated

2026-06-15

·

CVE-2021-26117

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ Artemis versions prior to 2.16.0 Apache ActiveMQ versions prior to 5.16.1 Apache ActiveMQ versions prior to 5.15.14
Description The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, the anonymous context is used to verify a valid user's password in error, resulting in no check on the password.
Recommendations For Apache ActiveMQ Artemis versions prior to 2.16.0, update to version 2.16.0 or later. For Apache ActiveMQ versions prior to 5.16.1, update to version 5.16.1 or later. For Apache ActiveMQ versions prior to 5.15.14, update to version 5.15.14 or later. As a temporary workaround, consider disabling the anonymous access to the LDAP server until a patch is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2021-26117
CVE-2021-26117
DLA-2583-1
DLA-3657-1
GHSA-9MGM-GCQ8-86WQ
USN-6910-1

Affected Products

Apache Activemq
Apache Activemq Artemis
Linuxmint
Ubuntu