← All CVEs

CVE-2021-26117

high · 7.5

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

7.5
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2021-01-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
apacheactivemq>= 5.15.0, < 5.15.14
apacheactivemq>= 5.16.0, < 5.16.1
apacheartemis< 2.16.0
netapponcommand_workflow_automationall versions
debiandebian_linux9.0
oraclecommunications_element_manager>= 8.2.0, <= 8.2.4.0
oraclecommunications_session_report_manager>= 8.2.0, <= 8.2.2
oraclecommunications_session_route_manager>= 8.0.0, <= 8.2.2
oracleflexcube_private_banking12.0.0
oracleflexcube_private_banking12.1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-26117