BIT-activemq-2020-11998

    Dashboard / Vulnerabilities / BIT-activemq-2020-11998

    BIT-activemq-2020-11998

    Published: 3 Dec 2025Last Modified: 8 Sept 2026

    Summary:

    Details: A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13

    Affected packages

    Package

    Name: activemq

    Purl: pkg:bitnami/activemq

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 5.15.12
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-activemq-2020-11998 | CVE-DB