CVE-2017-15709

LOW

Apache ActiveMQ 5.14.0-5.15.2 - Exposure of Sensitive System Information via OpenWire Protocol

Title source: llm
STIX 2.1

Description

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

Scores

CVSS v3 3.7
EPSS 0.6573
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
apache/activemq 5.14.0 - 5.15.2
org.apache.activemq/activemq-openwire-generator 5.14.0 - 5.15.3Maven
org.apache.activemq/activemq-parent 5.15.0 - 5.15.3Maven
Published Feb 13, 2018
Tracked Since Feb 18, 2026