Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11866

Опубликовано: 07 апр. 2026
Источник: fstec
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Уязвимость программных продуктов Apache ActiveMQ связана с неверным ограничением имени пути к каталогу. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, оказать воздействие на конфиденциальность защищаемой информации

Вендор

ООО «Ред Софт»
Apache Software Foundation
Axiom JDK

Наименование ПО

РЕД ОС
Apache ActiveMQ Client
Apache ActiveMQ Broker
Apache ActiveMQ
Apache ActiveMQ Web
Apache ActiveMQ All
Libercat EE Certified

Версия ПО

7.3 (РЕД ОС)
8.0 (РЕД ОС)
до 5.19.3 (Apache ActiveMQ Client)
от 6.0.0 до 6.2.2 (Apache ActiveMQ Client)
до 5.19.3 (Apache ActiveMQ Broker)
от 6.0.0 до 6.2.2 (Apache ActiveMQ Broker)
до 5.19.3 (Apache ActiveMQ)
от 6.0.0 до 6.2.2 (Apache ActiveMQ)
до 5.19.3 (Apache ActiveMQ Web)
от 6.0.0 до 6.2.2 (Apache ActiveMQ Web)
до 5.19.3 (Apache ActiveMQ All)
от 6.0.0 до 6.2.2 (Apache ActiveMQ All)
до 8.0.16-39 (Libercat EE Certified)
до 9.1.3-23 (Libercat EE Certified)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
ООО «Ред Софт» РЕД ОС 8.0
Axiom JDK Libercat EE Certified до 8.0.16-39
Axiom JDK Libercat EE Certified до 9.1.3-23

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 4,3)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://activemq.apache.org/security-advisories.data/CVE-2026-33227-announcement.txt
Для Ред ОС:
https://redos.red-soft.ru/search/?q=CVE-2026-33227

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 36%
0.00419
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.3
ubuntu
6 месяцев назад

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit. This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 an...

CVSS3: 4.3
redhat
6 месяцев назад

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit. This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 a...

CVSS3: 4.3
nvd
6 месяцев назад

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit. This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note:

CVSS3: 4.3
debian
6 месяцев назад

Improper validation and restriction of a classpath path name vulnerabi ...

CVSS3: 4.3
redos
около 2 месяцев назад

Уязвимость apache-activemq

EPSS

Процентиль: 36%
0.00419
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2