CVE-2021-26117: ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind

Published Sep 7, 2020
·
Updated

A flaw was found in activemq. When anonymous binds are enabled on the LDAP provider (zero length DN/password) and the LDAP module is configured to make use of these, client credentials are not correctly verified and authentication is effectively bypassed. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Other sources

A flaw was found in Red Hat AMQ 6 and ActiveMQ Artemis (Red Hat AMQ 7) with the LDAP login module, if anonymous binds are enabled on the LDAP provider (zero length DN/password) and the LDAP module is configured to make use of these, client credentials are not correctly verified and authentication is effectively bypassed.

Upstream Issue: https://issues.apache.org/jira/browse/ARTEMIS-2895

Red Hat

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

Affected Software

16 affected componentsFixes available
redhat/activemq-artemis-2.16.0 redhat-amq-7.8.0 redhat-amq<7.4.5
7.4.5
maven/org.apache.activemq:apache-artemis<2.16.0
2.16.0
maven/org.apache.activemq:activemq-parent<5.15.14
5.15.14
maven/org.apache.activemq:activemq-parent>=5.16.0<5.16.1
5.16.1
debian/activemq
5.16.1-15.16.1-1+deb11u15.17.2+dfsg-2+deb12u15.17.6+dfsg-1
Apache ActiveMQ>=5.15.0<5.15.14
Apache ActiveMQ>=5.16.0<5.16.1
Apache ActiveMQ Artemis<2.16.0
NetApp OnCommand Workflow Automation
Debian Debian Linux=9.0
Oracle Communications Element Manager>=8.2.0<=8.2.4.0
Oracle Communications Session Report Manager>=8.2.0<=8.2.2
Oracle Communications Session Route Manager>=8.0.0<=8.2.2
Oracle FLEXCUBE Private Banking=12.0.0
Oracle FLEXCUBE Private Banking=12.1.0
Apache ARTEMIS<2.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/activemq-artemis-2.16.0 redhat-amq-7.8.0 redhat-amq to a version that resolves this vulnerability.

    Fixed in 7.4.5
  2. Upgrade

    Upgrade maven/org.apache.activemq:apache-artemis to a version that resolves this vulnerability.

    Fixed in 2.16.0
  3. Upgrade

    Upgrade maven/org.apache.activemq:activemq-parent to a version that resolves this vulnerability.

    Fixed in 5.15.14
  4. Upgrade

    Upgrade maven/org.apache.activemq:activemq-parent to a version that resolves this vulnerability.

    Fixed in 5.16.1
  5. Upgrade

    Upgrade debian/activemq to a version that resolves this vulnerability.

    Fixed in 5.16.1-1Fixed in 5.16.1-1+deb11u1Fixed in 5.17.2+dfsg-2+deb12u1Fixed in 5.17.6+dfsg-1
  6. Upgrade

    Upgrade debian/activemq to a version that resolves this vulnerability.

    Fixed in 5.16.1-1
  7. Upgrade

    Upgrade debian/activemq to a version that resolves this vulnerability.

    Fixed in 5.16.1-1+deb11u1
  8. Upgrade

    Upgrade debian/activemq to a version that resolves this vulnerability.

    Fixed in 5.17.2+dfsg-2+deb12u1
  9. Upgrade

    Upgrade debian/activemq to a version that resolves this vulnerability.

    Fixed in 5.17.6+dfsg-1

Event History

Sep 7, 2020
CVE Published
03:15 PM
Data Sourced
03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 27, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 16, 2021
Advisory Published
via GitHub·05:39 PM
Jul 23, 2024
Data Sourced
via Launchpad·09:31 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·09:39 PM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for this flaw?

The vulnerability ID for this flaw is CVE-2021-26117.

2

What is the severity of CVE-2021-26117?

The severity of CVE-2021-26117 is high with a CVSS score of 8.1.

3

Which software packages are affected by CVE-2021-26117?

The affected software packages include activemq-artemis-2.16.0, redhat-amq-7.8.0, redhat-amq, Apache ActiveMQ, Apache ActiveMQ Artemis, NetApp OnCommand Workflow Automation, and Debian Debian Linux.

4

How can I fix CVE-2021-26117?

To fix CVE-2021-26117, you should apply the recommended remedy or update to version 7.4.5 for activemq-artemis-2.16.0, redhat-amq-7.8.0, and redhat-amq.

5

Where can I find more information about CVE-2021-26117?

You can find more information about CVE-2021-26117 at the following references: [Link 1](https://issues.apache.org/jira/browse/ARTEMIS-2895), [Link 2](https://www.openwall.com/lists/oss-security/2021/01/27/6), [Link 3](https://access.redhat.com/errata/RHSA-2021:0384).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203