Lucene search

K
cveApacheCVE-2021-26117
HistoryJan 27, 2021 - 7:15 p.m.

CVE-2021-26117

2021-01-2719:15:13
CWE-287
apache
web.nvd.nist.gov
114
26
cve
2021
26117
activemq
ldap
login module
anonymous access
security vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

51.0%

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

Affected configurations

Nvd
Vulners
Node
apacheactivemqRange5.15.05.15.14
OR
apacheactivemqRange5.16.05.16.1
OR
apacheactivemq_artemisRange<2.16.0
Node
netapponcommand_workflow_automationMatch-
Node
debiandebian_linuxMatch9.0
Node
oraclecommunications_element_managerRange8.2.08.2.4.0
OR
oraclecommunications_session_report_managerRange8.2.08.2.2
OR
oraclecommunications_session_route_managerRange8.0.08.2.2
OR
oracleflexcube_private_bankingMatch12.0.0
OR
oracleflexcube_private_bankingMatch12.1.0
VendorProductVersionCPE
apacheactivemq*cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
apacheactivemq_artemis*cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*:*
netapponcommand_workflow_automation-cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
debiandebian_linux9.0cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
oraclecommunications_element_manager*cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:*
oraclecommunications_session_report_manager*cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*
oraclecommunications_session_route_manager*cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*
oracleflexcube_private_banking12.0.0cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
oracleflexcube_private_banking12.1.0cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache ActiveMQ",
    "versions": [
      {
        "version": "Apache ActiveMQ Artemis",
        "status": "affected",
        "lessThan": "2.16.0",
        "versionType": "custom"
      },
      {
        "version": "Apache ActiveMQ",
        "status": "affected",
        "lessThan": "5.16.1",
        "versionType": "custom",
        "changes": [
          {
            "at": "5.15.14",
            "status": "unaffected"
          }
        ]
      }
    ]
  }
]

References

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

51.0%