Vulnerability Description
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Activemq | >= 5.0.0, <= 5.15.8 |
| Netapp | E-Series Santricity Web Services | - |
| Oracle | Communications Diameter Signaling Router | 8.0.0 |
| Oracle | Enterprise Manager Base Platform | 12.1.0.5.0 |
| Oracle | Enterprise Repository | 12.1.3.0.0 |
| Oracle | Goldengate Stream Analytics | < 19.1.0.0.1 |
| Oracle | Identity Manager Connector | 9.0 |
| Debian | Debian Linux | 9.0 |
References
- http://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.tMitigationThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/03/27/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/107622Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23
- https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966
- https://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4
- https://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d92521
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65
- https://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302
- https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e
- https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574
- https://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675
- https://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc
- https://lists.debian.org/debian-lts-announce/2021/03/msg00004.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00005.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2019-0222?
CVE-2019-0222 is a vulnerability with a CVSS score of 7.5 (HIGH). In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
How severe is CVE-2019-0222?
CVE-2019-0222 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0222?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Activemq, Netapp E-Series Santricity Web Services, Oracle Communications Diameter Signaling Router, Oracle Enterprise Manager Base Platform, Oracle Enterprise Repository.