cbcvebase.

Apache Activemq vulnerabilities

72 known vulnerabilities affecting apache/activemq.

Total CVEs
72
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
6
Severity breakdown
CRITICAL13HIGH29MEDIUM27LOW3

Vulnerabilities

Page 1 of 4
CVE-2023-46604P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 5.15.16≥ 5.16.0, < 5.16.7+2 more2023-10-27
CVE-2023-46604 [CRITICAL] CWE-502 CVE-2023-46604: The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability ma The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to i
nvdosv
CVE-2016-3088P1CRITICALCVSS 9.8KEVPoCRansomware≥ 5.0.0, < 5.14.02016-06-01
CVE-2016-3088 [CRITICAL] CWE-434 CVE-2016-3088: The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to uploa The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
nvdosv
CVE-2026-34197P1HIGHCVSS 8.8KEVPoCfixed in 5.19.4≥ 6.0.0, < 6.2.32026-04-07
CVE-2026-34197 [HIGH] CWE-20 CVE-2026-34197: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), includi
nvd
CVE-2018-8006P1MEDIUMCVSS 6.1ExploitedPoC≥ 5.0.0, ≤ 5.15.52018-10-10
CVE-2018-8006 [MEDIUM] CWE-79 CVE-2018-8006: An instance of a cross-site scripting vulnerability was identified to be present in the web based ad An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.
nvdosv
CVE-2024-32114P1HIGHCVSS 8.8ExploitedPoC≥ 6.0.0, < 6.1.22024-05-02
CVE-2024-32114 [HIGH] CWE-1188 CVE-2024-32114: In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolo In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the broker (using Jolokia JMX REST API) and/or produce/consume messages or purg
nvd
CVE-2026-40466P1HIGHCVSS 8.8ExploitedPoCfixed in 5.19.6≥ 6.0.0, < 6.2.52026-04-24
CVE-2026-40466 [HIGH] CVE-2026-40466: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Joloki
nvd
CVE-2013-7285P1CRITICALCVSS 9.8PoCv5.15.82019-05-15
CVE-2013-7285 [CRITICAL] CWE-78 CVE-2013-7285: Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initiali Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
nvd
CVE-2021-21345P1CRITICALCVSS 9.9PoCfixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21345 [CRITICAL] CWE-94 CVE-2021-21345: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security
nvd
CVE-2022-41678P1HIGHCVSS 8.8PoCfixed in 5.16.6≥ 5.17.0, < 5.17.42023-11-28
CVE-2022-41678 [HIGH] CWE-287 CVE-2022-41678: Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject. And calls to org.jolokia.http.HttpRequ
nvdosv
CVE-2020-26217P2HIGHCVSS 8.8PoCfixed in 5.15.14v5.16.02020-11-16
CVE-2020-26217 [HIGH] CWE-78 CVE-2020-26217: XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a r XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workaro
nvd
CVE-2021-21351P2CRITICALCVSS 9.1PoCfixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21351 [CRITICAL] CWE-434 CVE-2021-21351: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framewor
nvd
CVE-2015-1830P2MEDIUMCVSS 5.0PoCv5.0.0v5.1.0+20 more2015-08-19
CVE-2015-1830 [MEDIUM] CWE-22 CVE-2015-1830: Directory traversal vulnerability in the fileserver upload/download functionality for blob messages Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.
nvd
CVE-2021-21346P2CRITICALCVSS 9.8fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21346 [CRITICAL] CWE-434 CVE-2021-21346: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fr
nvd
CVE-2021-21344P2CRITICALCVSS 9.8fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21344 [CRITICAL] CWE-434 CVE-2021-21344: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fr
nvd
CVE-2020-11998P2CRITICALCVSS 9.8v5.15.122020-09-10
CVE-2020-11998 [CRITICAL] CVE-2020-11998: A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environme A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a java
nvd
CVE-2010-1587P3MEDIUMCVSS 5.0PoCv5.0.0v5.1.0+4 more2010-04-28
CVE-2010-1587 [MEDIUM] CWE-20 CVE-2010-1587: The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote a The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
nvd
CVE-2021-21342P2CRITICALCVSS 9.1fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21342 [CRITICAL] CWE-502 CVE-2021-21342: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the
nvd
CVE-2025-27533P3HIGHCVSS 7.5PoC≥ 5.16.0, < 5.16.8≥ 5.17.0, < 5.17.7+2 more2025-05-07
CVE-2025-27533 [HIGH] CWE-789 CVE-2025-27533: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rel
nvdosv
CVE-2015-5254P2CRITICALCVSS 9.8v5.0.0v5.1.0+22 more2016-01-08
CVE-2015-5254 [CRITICAL] CWE-20 CVE-2015-5254: Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
nvdosv
CVE-2021-21349P2HIGHCVSS 8.6fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21349 [HIGH] CWE-502 CVE-2021-21349: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4. XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream
nvd
Apache Activemq vulnerabilities | cvebase