Apache

Activemq

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.88%
  • Veröffentlicht 28.07.2026 13:33:54
  • Zuletzt bearbeitet 05.08.2026 18:46:44

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. T...

  • EPSS 0.49%
  • Veröffentlicht 28.07.2026 13:32:40
  • Zuletzt bearbeitet 05.08.2026 18:46:33

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physica...

  • EPSS 0.47%
  • Veröffentlicht 30.06.2026 09:55:29
  • Zuletzt bearbeitet 02.07.2026 18:43:25

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied tr...

  • EPSS 0.58%
  • Veröffentlicht 30.06.2026 09:54:38
  • Zuletzt bearbeitet 02.07.2026 18:43:35

Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-leng...

Medienbericht
  • EPSS 0.78%
  • Veröffentlicht 30.06.2026 09:53:42
  • Zuletzt bearbeitet 02.07.2026 18:42:59

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This i...

  • EPSS 0.54%
  • Veröffentlicht 30.06.2026 09:53:03
  • Zuletzt bearbeitet 02.07.2026 18:40:36

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large si...

  • EPSS 0.49%
  • Veröffentlicht 30.06.2026 09:51:57
  • Zuletzt bearbeitet 02.07.2026 18:42:47

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands ...

  • EPSS 0.47%
  • Veröffentlicht 30.06.2026 09:50:30
  • Zuletzt bearbeitet 02.07.2026 18:42:09

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an...

  • EPSS 0.54%
  • Veröffentlicht 30.06.2026 09:49:55
  • Zuletzt bearbeitet 02.07.2026 18:42:03

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker ...

Medienbericht
  • EPSS 1.18%
  • Veröffentlicht 30.06.2026 09:49:17
  • Zuletzt bearbeitet 02.07.2026 18:41:55

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encode...