CVE-2018-11775

HIGH

Apache ActiveMQ < 5.15.6 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

References (15)

Core 15
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041618
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105335
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3892
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/03/msg00005.html

Scores

CVSS v3 7.4
EPSS 0.0049
EPSS Percentile 65.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (8)
apache/activemq < 5.15.6
oracle/enterprise_repository 12.1.3.0.0
oracle/flexcube_private_banking 2.0.0.0
oracle/flexcube_private_banking 2.2.0.1
oracle/flexcube_private_banking 12.0.1.0
oracle/flexcube_private_banking 12.0.3.0
oracle/flexcube_private_banking 12.1.0.0
org.apache.activemq/activemq-client 0 - 5.15.6Maven
Published Sep 10, 2018
Tracked Since Feb 18, 2026