Tracker / CVE-2021-26117
CVE-2021-26117
High 7.5
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
Affected products and versions
| apache | activemq · 5.15.0 → 5.15.14 |
|---|---|
| apache | activemq · 5.16.0 → 5.16.1 |
| apache | artemis · … → 2.16.0 |
| debian | debian_linux |
| netapp | oncommand_workflow_automation |
| oracle | communications_element_manager · 8.2.0 → 8.2.4.0 |
| oracle | communications_session_report_manager · 8.2.0 → 8.2.2 |
| oracle | communications_session_route_manager · 8.0.0 → 8.2.2 |
| oracle | flexcube_private_banking |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.