CVE-2021-26117
published 2021-01-27CVE-2021-26117: The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to…
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
11.24%
95.5th percentile
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | >= 0 < 5.16.1-1 | 5.16.1-1 |
| apache | activemq | >= 0 < 5.16.1-1 | 5.16.1-1 |
| apache | activemq | >= 0 < 5.16.1-1 | 5.16.1-1 |
| apache | activemq | >= 0 < 5.13.2+dfsg-2ubuntu0.1~esm1 | 5.13.2+dfsg-2ubuntu0.1~esm1 |
| apache | activemq | >= 0 < 5.15.8-2~18.04.1~esm1 | 5.15.8-2~18.04.1~esm1 |
| apache | activemq | >= 0 < 5.15.11-1ubuntu0.1~esm1 | 5.15.11-1ubuntu0.1~esm1 |
| apache | activemq | >= 0 < 5.16.1-1ubuntu0.1~esm1 | 5.16.1-1ubuntu0.1~esm1 |
| apache | activemq | >= 5.15.0 < 5.15.14 | 5.15.14 |
| apache | activemq | >= 5.16.0 < 5.16.1 | 5.16.1 |
| apache | artemis | < 2.16.0 | 2.16.0 |
| apache_software_foundation | apache_activemq | >= Apache ActiveMQ < 5.16.1 | 5.16.1 |
| apache_software_foundation | apache_activemq | >= Apache ActiveMQ Artemis < 2.16.0 | 2.16.0 |
| debian | activemq | < activemq 5.16.1-1 (bookworm) | activemq 5.16.1-1 (bookworm) |
| debian | debian_linux | — | — |
| oracle | communications_element_manager | 8.2.0 – 8.2.4.0 | — |
| oracle | communications_session_report_manager | 8.2.0 – 8.2.2 | — |
| oracle | communications_session_route_manager | 8.0.0 – 8.2.2 | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_oracle9.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
activemq vulnerabilities
osv·2024-07-23·CVSS 2.7
CVE-2015-7559 [LOW] activemq vulnerabilities
activemq vulnerabilities
Chess Hazlett discovered that Apache ActiveMQ incorrectly handled certain
commands. A remote attacker could possibly use this issue to terminate
the program, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2015-7559)
Peter Stöckli discovered that Apache ActiveMQ incorrectly handled
hostname verification. A remote attacker could possibly use this issue
to perform a person-in-the-middle attack. This issue only affected Ubuntu
16.04 LTS. (CVE-2018-11775)
Jonathan Gallimore and Colm Ó hÉigeartaigh discovered that Apache
ActiveMQ incorrectly handled authentication in certain functions.
A remote attacker could possibly use this issue to perform a
person-in-the-middle attack. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS
OSV
Improper Authentication in Apache ActiveMQ and Apache Artemis
osv·2021-06-16
CVE-2021-26117 [HIGH] Improper Authentication in Apache ActiveMQ and Apache Artemis
Improper Authentication in Apache ActiveMQ and Apache Artemis
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
GHSA
Improper Authentication in Apache ActiveMQ and Apache Artemis
ghsa·2021-06-16
CVE-2021-26117 [HIGH] CWE-287 Improper Authentication in Apache ActiveMQ and Apache Artemis
Improper Authentication in Apache ActiveMQ and Apache Artemis
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
OSV
CVE-2021-26117: The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server
osv·2021-01-27·CVSS 7.5
CVE-2021-26117 [HIGH] CVE-2021-26117: The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
Ubuntu
Apache ActiveMQ vulnerabilities
vendor_ubuntu·2024-07-23·CVSS 2.7
CVE-2021-26117 [LOW] Apache ActiveMQ vulnerabilities
Title: Apache ActiveMQ vulnerabilities
Summary: Several security issues were fixed in Apache ActiveMQ.
Chess Hazlett discovered that Apache ActiveMQ incorrectly handled certain
commands. A remote attacker could possibly use this issue to terminate
the program, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2015-7559)
Peter Stöckli discovered that Apache ActiveMQ incorrectly handled
hostname verification. A remote attacker could possibly use this issue
to perform a person-in-the-middle attack. This issue only affected Ubuntu
16.04 LTS. (CVE-2018-11775)
Jonathan Gallimore and Colm Ó hÉigeartaigh discovered that Apache
ActiveMQ incorrectly handled authentication in certain functions.
A remote attacker could possibly use this issue to perform a
person-in-
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache ActiveMQ) — CVE-2021-26117
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2021-26117 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: General (Apache ActiveMQ) — CVE-2021-26117
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache ActiveMQ) vulnerability
CVE: CVE-2021-26117
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Financial Planning (Apache ActiveMQ) — CVE-2021-26117
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2021-26117 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Financial Planning (Apache ActiveMQ) — CVE-2021-26117
Oracle Oracle Financial Services Applications Risk Matrix: Financial Planning (Apache ActiveMQ) vulnerability
CVE: CVE-2021-26117
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Debian
CVE-2021-26117: activemq - The optional ActiveMQ LDAP login module can be configured to use anonymous acces...
vendor_debian·2021·CVSS 7.5
CVE-2021-26117 [HIGH] CVE-2021-26117: activemq - The optional ActiveMQ LDAP login module can be configured to use anonymous acces...
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
Scope: local
bookworm: resolved (fixed in 5.16.1-1)
bullseye: resolved (fixed in 5.16.1-1)
sid: resolved (fixed in 5.16.1-1)
trixie: resolved (fixed in 5.16.1-1)
Red Hat
activemq: LDAP authentication bypass with anonymous bind
vendor_redhat·2020-09-07·CVSS 7.5
CVE-2021-26117 [HIGH] CWE-287 activemq: LDAP authentication bypass with anonymous bind
activemq: LDAP authentication bypass with anonymous bind
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
A flaw was found in activemq. When anonymous binds are enabled on the LDAP provider (zero length DN/password) and the LDAP module is configured to make use of these, client credentials are not correctly verified and authentication is effectively bypassed. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Mitigation: There is currently
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r110cacfa754471361234965ffe851a046e302ff2693b055f49f47b02%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r22cdc0fb45e223ac92bc2ceff7af92f1193dfc614c8b248534456229%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r3341d96d8f956e878fb7b463b08d57ca1d58fec9c970aee929b58e0d%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r519bfafd67091d0b91243efcb1c49b1eea27321355ba5594f679277d%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r5899ece90bcae5805ad6142fdb05c58595cff19cb2e98cc58a91f55b%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r70389648227317bdadcdecbd9f238571a6047469d156bd72bb0ca2f7%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ra255ddfc8b613b80e9fa22ff3e106168b245f38a22316bfb54d21159%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/raea451de09baed76950d6a60cc4bb1b74476c505e03205a3c68c9808%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rd05b1c9d61dbd220664d559aa0e2b55e5830f006a09e82057f3f7863%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rd75600cee29cb248d548edcf6338fe296466d63a69e2ed0afc439ec7%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re1b98da90a5f2e1c2e2d50e31c12e2578d61fe01c0737f9d0bd8de99%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rec93794f8aeddf8a5f1a643d264b4e66b933f06fd72a38f31448f0ac%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rffa5cd05d01c4c9853b17f3004d80ea6eb8856c422a8545c5f79b1a6%40%3Ccommits.activemq.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2023/11/msg00013.htmlhttps://mail-archives.apache.org/mod_mbox/activemq-users/202101.mbox/%3cCAH+vQmMeUEiKN4wYX9nLBbqmFZFPXqajNvBKmzb2V8QZANcSTA%40mail.gmail.com%3ehttps://security.netapp.com/advisory/ntap-20210304-0008/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/r110cacfa754471361234965ffe851a046e302ff2693b055f49f47b02%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r22cdc0fb45e223ac92bc2ceff7af92f1193dfc614c8b248534456229%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r3341d96d8f956e878fb7b463b08d57ca1d58fec9c970aee929b58e0d%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r519bfafd67091d0b91243efcb1c49b1eea27321355ba5594f679277d%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r5899ece90bcae5805ad6142fdb05c58595cff19cb2e98cc58a91f55b%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r70389648227317bdadcdecbd9f238571a6047469d156bd72bb0ca2f7%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ra255ddfc8b613b80e9fa22ff3e106168b245f38a22316bfb54d21159%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/raea451de09baed76950d6a60cc4bb1b74476c505e03205a3c68c9808%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rd05b1c9d61dbd220664d559aa0e2b55e5830f006a09e82057f3f7863%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rd75600cee29cb248d548edcf6338fe296466d63a69e2ed0afc439ec7%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re1b98da90a5f2e1c2e2d50e31c12e2578d61fe01c0737f9d0bd8de99%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rec93794f8aeddf8a5f1a643d264b4e66b933f06fd72a38f31448f0ac%40%3Cgitbox.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rffa5cd05d01c4c9853b17f3004d80ea6eb8856c422a8545c5f79b1a6%40%3Ccommits.activemq.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2023/11/msg00013.htmlhttps://mail-archives.apache.org/mod_mbox/activemq-users/202101.mbox/%3cCAH+vQmMeUEiKN4wYX9nLBbqmFZFPXqajNvBKmzb2V8QZANcSTA%40mail.gmail.com%3ehttps://security.netapp.com/advisory/ntap-20210304-0008/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-01-27
Published