CVE-2018-11775
10.09.2018, 20:29
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.Enginsight
Vendor | Product | Version |
---|---|---|
apache | activemq | 𝑥 < 5.15.6 |
oracle | enterprise_repository | 12.1.3.0.0 |
oracle | flexcube_private_banking | 2.0.0.0 |
oracle | flexcube_private_banking | 2.2.0.1 |
oracle | flexcube_private_banking | 12.0.1.0 |
oracle | flexcube_private_banking | 12.0.3.0 |
oracle | flexcube_private_banking | 12.1.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
activemq |
|
Common Weakness Enumeration
References