CVE-2020-13931
Description
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.368
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2020-13931 are fixed in Apache - apache-tomee 8.0.4 | Windows |
| Vulnerabilities CVE-2020-13931 are fixed in Apache - apache-tomee 7.1.4 | Windows |
| Vulnerabilities CVE-2020-13931 are fixed in Apache - apache-tomee 7.0.9 | Windows |
| Vulnerabilities CVE-2020-13931 are fixed in Apache - apache-tomee for Linux 8.0.4 | Linux |
| Vulnerabilities CVE-2020-13931 are fixed in Apache - apache-tomee for Linux 7.1.4 | Linux |
| Vulnerabilities CVE-2020-13931 are fixed in Apache - apache-tomee for Linux 7.0.9 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234