Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26733
HistorySep 11, 2020 - 5:01 a.m.

Man-in-the-Middle (MitM)

2020-09-1105:01:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.003 Low

EPSS

Percentile

70.8%

activemq-broker is vulnerable to man-in-the-middle(MitM) attack. It binds the server to jmxrmi entry after creating JMX RMI registry using LocateRegistry.createRegistry(), leading to the connection to the registry without authentication and allowing rebinding of jmxrmi to any other entity. Therefore, if an attacker can successfully create a malicious server to proxy the original and perform RMI rebinding when a user connects, confidential information can be intercepted.