Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to pub
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N약점 (CWE)
- CWE-20
부적절한 입력 검증 — 입력값 검증 부족으로 다양한 후속 공격에 노출.
상세 설명
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- apache activemq< 5.19.8other
- apache activemq6.0.0 - 6.2.7other
- apache activemq_broker< 5.19.8other
- apache activemq_broker6.0.0 - 6.2.7other
영향받는 구성 (CPE) 2
- apache activemq< 5.19.8cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
- apache activemq_broker< 5.19.8cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
참고 자료 2
- http://www.openwall.com/lists/oss-security/2026/06/29/8Third Party Advisory
링크 내용 불러오는 중…