CVE-2017-15709
published 2018-02-13CVE-2017-15709: When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed…
PriorityP424low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
23.25%
97.5th percentile
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | >= 0 < 5.15.3-1 | 5.15.3-1 |
| apache | activemq | >= 0 < 5.15.3-1 | 5.15.3-1 |
| apache | activemq | >= 0 < 5.15.3-1 | 5.15.3-1 |
| apache | activemq | 5.14.0 – 5.15.2 | — |
| apache_software_foundation | apache_activemq | — | — |
| debian | activemq | < activemq 5.15.3-1 (bookworm) | activemq 5.15.3-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability affects ActiveMQ when using the OpenWire protocol; monitor for OpenWire protocol traffic that leaks OS and kernel version details in plain text ↗
- →Scope of exposure is local; focus detection on local access to ActiveMQ OpenWire protocol responses containing system detail disclosures ↗
- ·Only ActiveMQ versions 5.14.0 through 5.15.2 are affected; versions fixed at 5.15.3 and above are not vulnerable ↗
- ·Red Hat JBoss Fuse 6 Broker package is confirmed not affected; Red Hat JBoss Fuse Service Works 6 is out of support scope for this CVE ↗
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ActiveMQ's OpenWire protocol exposes certain system details as plain text
ghsa·2022-05-13
CVE-2017-15709 [LOW] CWE-200 ActiveMQ's OpenWire protocol exposes certain system details as plain text
ActiveMQ's OpenWire protocol exposes certain system details as plain text
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
OSV
ActiveMQ's OpenWire protocol exposes certain system details as plain text
osv·2022-05-13
CVE-2017-15709 [LOW] ActiveMQ's OpenWire protocol exposes certain system details as plain text
ActiveMQ's OpenWire protocol exposes certain system details as plain text
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
OSV
CVE-2017-15709: When using the OpenWire protocol in ActiveMQ versions 5
osv·2018-02-13·CVSS 3.7
CVE-2017-15709 [LOW] CVE-2017-15709: When using the OpenWire protocol in ActiveMQ versions 5
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Red Hat
activemq-openwire-generator: Information Exposure in ActiveMQ
vendor_redhat·2018-02-13·CVSS 3.7
CVE-2017-15709 [LOW] CWE-200 activemq-openwire-generator: Information Exposure in ActiveMQ
activemq-openwire-generator: Information Exposure in ActiveMQ
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Package: Broker (Red Hat JBoss Fuse 6) - Not affected
Package: activemq-openwire-generator (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Debian
CVE-2017-15709: activemq - When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was fo...
vendor_debian·2017·CVSS 3.7
CVE-2017-15709 [LOW] CVE-2017-15709: activemq - When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was fo...
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Scope: local
bookworm: resolved (fixed in 5.15.3-1)
bullseye: resolved (fixed in 5.15.3-1)
sid: resolved (fixed in 5.15.3-1)
trixie: resolved (fixed in 5.15.3-1)
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/2b6f04a552c6ec2de6563c2df3bba813f0fe9c7e22cce27b7829db89%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/3f1e41bc9153936e065ca3094bd89ff8167ad2d39ac0b410f24382d2%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/c0ec53b72b3240b187afb1cf67e4309a9e5f607282010aa196734814%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b%40%3Cdev.activemq.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00005.htmlhttps://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/2b6f04a552c6ec2de6563c2df3bba813f0fe9c7e22cce27b7829db89%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/3f1e41bc9153936e065ca3094bd89ff8167ad2d39ac0b410f24382d2%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/c0ec53b72b3240b187afb1cf67e4309a9e5f607282010aa196734814%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b%40%3Cdev.activemq.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00005.html
2018-02-13
Published