CVE-2020-13947

MEDIUM

Apache ActiveMQ 5.15.12-5.16.0 - Stored Cross-Site Scripting in message.jsp

Title source: llm
STIX 2.1

Description

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

Scores

CVSS v3 6.1
EPSS 0.0403
EPSS Percentile 88.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
apache/activemq < 5.15.14
oracle/communications_session_report_manager 8.0.0 - 8.2.2
oracle/communications_session_route_manager 8.0.0 - 8.2.2
org.apache.activemq/activemq-parent 5.16.0 - 5.16.1Maven
Published Feb 08, 2021
Tracked Since Feb 18, 2026