Skip to main content

CVE-2017-15709

Severity

3.7

Description

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

Mitigation

We recommend upgrading to a version of this component that is not vulnerable to this specific issue, or use a TLS-enabled transport method in place of the OpenWire protocol.

Project

Apache TomEE

Apache ActiveMQ

Category
Information Leak
Tags
data
Date Disclosed

2018-02-13

Date Discovered

2017-10-21

Apache TomEE 7.1.x

First release:
2018-09-02
0
Support Lifecycle:
Namespace:
javax

Apache TomEE 7.0.x

First release:
2016-05-17
0
Support Lifecycle:
Namespace:
javax

Apache ActiveMQ 5.15.x

First release:
2017-06-27
0
Support Lifecycle:
Namespace:
javax

Apache ActiveMQ 5.14.x

First release:
2016-08-02
0
Support Lifecycle:
Namespace:
javax
Feel Vulnerable? 

Contact us so we can help you.

* These fields are required.