cbcvebase.
CVE-2017-15709
published 2018-02-13

CVE-2017-15709: When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed…

PriorityP424low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
23.25%
97.5th percentile
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

Affected

6 ranges
VendorProductVersion rangeFixed in
apacheactivemq>= 0 < 5.15.3-15.15.3-1
apacheactivemq>= 0 < 5.15.3-15.15.3-1
apacheactivemq>= 0 < 5.15.3-15.15.3-1
apacheactivemq5.14.0 – 5.15.2
apache_software_foundationapache_activemq
debianactivemq< activemq 5.15.3-1 (bookworm)activemq 5.15.3-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability affects ActiveMQ when using the OpenWire protocol; monitor for OpenWire protocol traffic that leaks OS and kernel version details in plain text
  • Scope of exposure is local; focus detection on local access to ActiveMQ OpenWire protocol responses containing system detail disclosures
  • ·Only ActiveMQ versions 5.14.0 through 5.15.2 are affected; versions fixed at 5.15.3 and above are not vulnerable
  • ·Red Hat JBoss Fuse 6 Broker package is confirmed not affected; Red Hat JBoss Fuse Service Works 6 is out of support scope for this CVE

CVSS provenance

nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.