4.3
CVSSv2

CVE-2017-15709

Published: 13/02/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache activemq

Vendor Advisories

Debian Bug report logs - #890352 activemq: CVE-2017-15709: information leak Package: src:activemq; Maintainer for src:activemq is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 13 Feb 2018 20:33:02 UTC Severity: important Tags: ...
When using the OpenWire protocol in ActiveMQ versions 5140 to 5152 it was found that certain system details (such as the OS and kernel version) are exposed as plain text ...