PT-2021-16958 · Apache+2 · Apache Activemq+3
Published
2021-01-27
·
Updated
2026-06-15
·
CVE-2021-26117
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ Artemis versions prior to 2.16.0
Apache ActiveMQ versions prior to 5.16.1
Apache ActiveMQ versions prior to 5.15.14
Description
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, the anonymous context is used to verify a valid user's password in error, resulting in no check on the password.
Recommendations
For Apache ActiveMQ Artemis versions prior to 2.16.0, update to version 2.16.0 or later.
For Apache ActiveMQ versions prior to 5.16.1, update to version 5.16.1 or later.
For Apache ActiveMQ versions prior to 5.15.14, update to version 5.15.14 or later.
As a temporary workaround, consider disabling the anonymous access to the LDAP server until a patch is available.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Activemq
Apache Activemq Artemis
Linuxmint
Ubuntu