CVE Vulnerabilities

CVE-2020-13931

Published: Dec 18, 2020 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.

Affected Software

Name Vendor Start Version End Version
Tomee Apache 1.0.0 (including) 1.7.5 (including)
Tomee Apache 7.0.0 (including) 7.0.8 (including)
Tomee Apache 7.1.0 (including) 7.1.3 (including)
Tomee Apache 8.0.0 (including) 8.0.3 (including)
Tomee Apache 7.0.0-m1 (including) 7.0.0-m1 (including)
Tomee Apache 7.0.0-m2 (including) 7.0.0-m2 (including)
Tomee Apache 7.0.0-m3 (including) 7.0.0-m3 (including)
Tomee Apache 8.0.0-m1 (including) 8.0.0-m1 (including)

References