CVE-2018-11775: High severity apache activemq vulnerability
Apache ActiveMQ Client could allow a remote attacker to conduct a man-in-the-middle attack, caused by a missing TLS hostname verification. An attacker could exploit this vulnerability to launch a man-in-the-middle attack between a Java application using the ActiveMQ client and the ActiveMQ server.
Other sources
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-11775.
What is the severity level of CVE-2018-11775?
CVE-2018-11775 has a severity level of 7.4 (High).
What is the affected software for CVE-2018-11775?
The affected software for CVE-2018-11775 includes Apache ActiveMQ Client before version 5.15.6, Oracle Enterprise Repository version 12.1.3.0.0, Oracle FLEXCUBE Private Banking versions 2.0.0.0, 2.2.0.1, 12.0.1.0, 12.0.3.0, 12.1.0.0, and IBM Security Directory Suite VA up to version 8.0.1-8.0.1.19.
What is the impact of the vulnerability CVE-2018-11775?
The vulnerability CVE-2018-11775 allows a remote attacker to conduct a man-in-the-middle attack between a Java application using the ActiveMQ client and the ActiveMQ server.
How can I fix the vulnerability CVE-2018-11775?
To fix the vulnerability CVE-2018-11775, update the Apache ActiveMQ Client to version 5.15.6 or later.