CVE-2017-15709

Description

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

Risk Information

Base Score
3.7
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
65.728

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-15709 are fixed in Apache - activemq-parent 5.15.3Windows
Vulnerabilities CVE-2017-15709 are fixed in Apache - activemq-parent 5.14.6Windows
Vulnerabilities CVE-2017-15709 are fixed in Apache-activemq-openwire-generator 5.15.3Windows
Vulnerabilities CVE-2017-15709 are fixed in Apache - activemq-parent for Linux 5.15.3Linux
Vulnerabilities CVE-2017-15709 are fixed in Apache - activemq-parent for Linux 5.14.6Linux
Vulnerabilities CVE-2017-15709 are fixed in Apache-activemq-openwire-generator for Linux 5.15.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234