Vulnerability Description
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Activemq | >= 5.14.0, <= 5.15.2 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23
- https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966
- https://lists.apache.org/thread.html/2b6f04a552c6ec2de6563c2df3bba813f0fe9c7e22c
- https://lists.apache.org/thread.html/3f1e41bc9153936e065ca3094bd89ff8167ad2d39ac
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65
- https://lists.apache.org/thread.html/c0ec53b72b3240b187afb1cf67e4309a9e5f6072820
- https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e
- https://lists.debian.org/debian-lts-announce/2021/03/msg00005.html
- https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23
- https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966
- https://lists.apache.org/thread.html/2b6f04a552c6ec2de6563c2df3bba813f0fe9c7e22c
- https://lists.apache.org/thread.html/3f1e41bc9153936e065ca3094bd89ff8167ad2d39ac
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65
- https://lists.apache.org/thread.html/c0ec53b72b3240b187afb1cf67e4309a9e5f6072820
- https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e
FAQ
What is CVE-2017-15709?
CVE-2017-15709 is a vulnerability with a CVSS score of 3.7 (LOW). When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
How severe is CVE-2017-15709?
CVE-2017-15709 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15709?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Activemq.