imPC@ndo IT

Tracker / CVE-2021-26117

CVE-2021-26117

High 7.5

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.

Affected products and versions

apache activemq · 5.15.0 → 5.15.14
apache activemq · 5.16.0 → 5.16.1
apache artemis · … → 2.16.0
debian debian_linux
netapp oncommand_workflow_automation
oracle communications_element_manager · 8.2.0 → 8.2.4.0
oracle communications_session_report_manager · 8.2.0 → 8.2.2
oracle communications_session_route_manager · 8.0.0 → 8.2.2
oracle flexcube_private_banking

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References