Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-26118

Опубликовано: 27 янв. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:activemq_artemis:2.15.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.0101
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

CVSS3: 7.5
redhat
больше 5 лет назад

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

CVSS3: 7.5
github
больше 4 лет назад

Apache ActiveMQ Artemis vulnerable to Improper Access Control

EPSS

Процентиль: 77%
0.0101
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other