CVE-2018-11775 PUBLISHED

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

EPSS 0.49% · 65.4th percentile

Risk Scores

EPSS Score
0.49%
65.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSactivemq0, 5.6.0+dfsg1-4+deb8u1ubuntu1, 5.6.0+dfsg1-5

Timeline

References

Open in Interactive Console →