CVE-2024-8689

MEDIUM

Cortex XSOAR/XSIAM - Info Disclosure

Title source: llm
STIX 2.1

Description

A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.

References (1)

Core 1
Core References

Scores

CVSS v4 6.0
EPSS 0.0021
EPSS Percentile 11.5%
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:M/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
Palo Alto Networks/ActiveMQ Content Pack 1.1.0 - 1.1.15
Published Sep 11, 2024
Tracked Since Feb 18, 2026