9.8

CVE-2020-13931

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.

Data is provided by the National Vulnerability Database (NVD)
ApacheTomee Version >= 1.0.0 <= 1.7.5
ApacheTomee Version >= 7.0.0 <= 7.0.8
ApacheTomee Version >= 7.1.0 <= 7.1.3
ApacheTomee Version >= 8.0.0 <= 8.0.3
ApacheTomee Version7.0.0 Updatem1
ApacheTomee Version7.0.0 Updatem2
ApacheTomee Version7.0.0 Updatem3
ApacheTomee Version8.0.0 Updatem1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.37% 0.794
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P