Логотип exploitDog
bind:CVE-2020-13920
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-13920

Количество 5

Количество 5

ubuntu логотип

CVE-2020-13920

больше 5 лет назад

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2020-13920

больше 5 лет назад

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2020-13920

больше 5 лет назад

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2020-13920

больше 5 лет назад

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xgrx-xpv2-6vp4

почти 4 года назад

Improper Authentication in Apache ActiveMQ

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVSS3: 5.9
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVSS3: 5.9
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVSS3: 5.9
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX ...

CVSS3: 5.9
0%
Низкий
больше 5 лет назад
github логотип
GHSA-xgrx-xpv2-6vp4

Improper Authentication in Apache ActiveMQ

CVSS3: 5.9
0%
Низкий
почти 4 года назад

Уязвимостей на страницу