CVE-2017-15709: Infoleak
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-15709.
What is the severity level of CVE-2017-15709?
The severity level of CVE-2017-15709 is medium with a severity value of 3.7.
Which versions of ActiveMQ are affected by CVE-2017-15709?
ActiveMQ versions 5.14.0 to 5.15.2 are affected by CVE-2017-15709.
What system details are exposed as plain text in ActiveMQ versions 5.14.0 to 5.15.2?
In ActiveMQ versions 5.14.0 to 5.15.2, certain system details such as the OS and kernel version are exposed as plain text.
Are there any references for CVE-2017-15709?
Yes, there are references for CVE-2017-15709. You can find them at the following links: [Reference 1](https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1@%3Cdev.activemq.apache.org%3E), [Reference 2](https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc@%3Ccommits.activemq.apache.org%3E), [Reference 3](https://lists.apache.org/thread.html/2b6f04a552c6ec2de6563c2df3bba813f0fe9c7e22cce27b7829db89@%3Cdev.activemq.apache.org%3E).