Vulnerability Name: | CVE-2017-15709 (CCN-139028) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2017-10-21 | ||||||||||||||||||||||||||||||||||||
Published: | 2018-02-13 | ||||||||||||||||||||||||||||||||||||
Updated: | 2021-03-05 | ||||||||||||||||||||||||||||||||||||
Summary: | When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) 3.2 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||
References: | Source: CCN Type: Apache Web site ActiveMQ Source: MITRE Type: CNA CVE-2017-15709 Source: CCN Type: oss-sec Mailing List, Tue, 13 Feb 2018 07:06:47 -0500 [ANNOUNCE] CVE-2017-15709 - Information Leak Source: XF Type: UNKNOWN apache-activemq-cve201715709-info-disc(139028) Source: MLIST Type: Mailing List, Vendor Advisory [activemq-dev] 20190328 Re: Website Source: MLIST Type: Mailing List, Vendor Advisory [activemq-commits] 20190327 [CONF] Apache ActiveMQ > Security Advisories Source: MISC Type: Mailing List, Vendor Advisory https://lists.apache.org/thread.html/2b6f04a552c6ec2de6563c2df3bba813f0fe9c7e22cce27b7829db89@%3Cdev.activemq.apache.org%3E Source: MLIST Type: UNKNOWN [activemq-gitbox] 20191021 [GitHub] [activemq-website] clebertsuconic commented on a change in pull request #17: Fix the ordering in the security advisories page Source: MLIST Type: Mailing List, Vendor Advisory [activemq-commits] 20190327 svn commit: r1042639 - in /websites/production/activemq/content/activemq-website: ./ projects/artemis/download/ projects/classic/download/ projects/cms/download/ security-advisories.data/ Source: MLIST Type: UNKNOWN [activemq-gitbox] 20191022 [GitHub] [activemq-website] coheigea commented on a change in pull request #17: Fix the ordering in the security advisories page Source: MLIST Type: Mailing List, Vendor Advisory [activemq-dev] 20190327 Re: Website Source: MLIST Type: UNKNOWN [debian-lts-announce] 20210305 [SECURITY] [DLA 2583-1] activemq security update Source: CCN Type: IBM Security Bulletin 6344071 (QRadar SIEM) IBM QRadar SIEM is vulnerable to Using Components with Known Vulnerabilities | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |