CVE Vulnerabilities

CVE-2020-13931

Published: Dec 18, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.

Affected Software

NameVendorStart VersionEnd Version
TomeeApache1.0.0 (including)1.7.5 (including)
TomeeApache7.0.0 (including)7.0.8 (including)
TomeeApache7.1.0 (including)7.1.3 (including)
TomeeApache8.0.0 (including)8.0.3 (including)
TomeeApache7.0.0-m1 (including)7.0.0-m1 (including)
TomeeApache7.0.0-m2 (including)7.0.0-m2 (including)
TomeeApache7.0.0-m3 (including)7.0.0-m3 (including)
TomeeApache8.0.0-m1 (including)8.0.0-m1 (including)

References