CVE-2017-15709

EUVD-2022-3050
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
apacheactivemq
5.14.0 ≤
𝑥
≤ 5.15.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
activemq
bookworm
5.17.2+dfsg-2
fixed
bookworm (security)
5.17.2+dfsg-2+deb12u1
fixed
bullseye
5.16.1-1
fixed
bullseye (security)
5.16.1-1+deb11u1
fixed
jessie
not-affected
sid
5.17.6+dfsg-1
fixed
trixie
5.17.6+dfsg-1
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
activemq
artful
ignored
bionic
not-affected
cosmic
not-affected
trusty
dne
xenial
not-affected
References