The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
20 Nov 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Nov 2023, 03:31
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
07 Dec 2021, 20:47
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.oracle.com/security-alerts/cpuoct2021.html - Patch, Third Party Advisory | |
References | (N/A) https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory | |
CPE | cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* |
20 Oct 2021, 11:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
17 Jun 2021, 17:16
Type | Values Removed | Values Added |
---|---|---|
References | (MLIST) https://lists.apache.org/thread.html/r3341d96d8f956e878fb7b463b08d57ca1d58fec9c970aee929b58e0d@%3Cissues.activemq.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/ra255ddfc8b613b80e9fa22ff3e106168b245f38a22316bfb54d21159@%3Cissues.activemq.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rd05b1c9d61dbd220664d559aa0e2b55e5830f006a09e82057f3f7863@%3Cissues.activemq.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuApr2021.html - Not Applicable, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r519bfafd67091d0b91243efcb1c49b1eea27321355ba5594f679277d@%3Cissues.activemq.apache.org%3E - Mailing List, Third Party Advisory |
14 Jun 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 May 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 May 2021, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Apr 2021, 16:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | (MLIST) https://lists.apache.org/thread.html/r5899ece90bcae5805ad6142fdb05c58595cff19cb2e98cc58a91f55b@%3Cgitbox.activemq.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rec93794f8aeddf8a5f1a643d264b4e66b933f06fd72a38f31448f0ac@%3Cgitbox.activemq.apache.org%3E - Mailing List, Third Party Advisory |
09 Apr 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Mar 2021, 18:50
Type | Values Removed | Values Added |
---|---|---|
References | (MLIST) https://lists.apache.org/thread.html/r70389648227317bdadcdecbd9f238571a6047469d156bd72bb0ca2f7@%3Cgitbox.activemq.apache.org%3E - Mailing List, Patch, Third Party Advisory |
23 Mar 2021, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Mar 2021, 18:23
Type | Values Removed | Values Added |
---|---|---|
References | (MLIST) https://lists.debian.org/debian-lts-announce/2021/03/msg00005.html - Mailing List, Third Party Advisory | |
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20210304-0008/ - Third Party Advisory | |
CPE | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
05 Mar 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Mar 2021, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Feb 2021, 01:11
Type | Values Removed | Values Added |
---|---|---|
References | (MLIST) https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7@%3Ccommits.activemq.apache.org%3E - Mailing List, Patch, Vendor Advisory |
08 Feb 2021, 07:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Feb 2021, 15:54
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:apache:activemq_artemis:*:*:*:*:*:*:*:* cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* |
|
References | (MLIST) https://lists.apache.org/thread.html/re1b98da90a5f2e1c2e2d50e31c12e2578d61fe01c0737f9d0bd8de99@%3Cannounce.apache.org%3E - Mailing List, Vendor Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rffa5cd05d01c4c9853b17f3004d80ea6eb8856c422a8545c5f79b1a6@%3Ccommits.activemq.apache.org%3E - Mailing List, Vendor Advisory | |
References | (MISC) https://mail-archives.apache.org/mod_mbox/activemq-users/202101.mbox/%3cCAH+vQmMeUEiKN4wYX9nLBbqmFZFPXqajNvBKmzb2V8QZANcSTA@mail.gmail.com%3e - Mailing List, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
CWE | CWE-287 |
28 Jan 2021, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Jan 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Jan 2021, 20:20
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-01-27 19:15
Updated : 2023-11-20 22:15
NVD link : CVE-2021-26117
Mitre link : CVE-2021-26117
CVE.ORG link : CVE-2021-26117
JSON object : View
Products Affected
oracle
- communications_session_route_manager
- communications_session_report_manager
- communications_element_manager
- flexcube_private_banking
netapp
- oncommand_workflow_automation
apache
- activemq
- activemq_artemis
debian
- debian_linux
CWE
CWE-287
Improper Authentication