DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2025-27533

High
Low Medium High Critical
7.5
CVSS Score
Published: May 07, 2025
Last Modified: Nov 03, 2025

Vulnerability Description

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.

During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.
This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.

Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.

Existing users may implement mutual TLS to mitigate the risk on affected brokers.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
N
Integrity
N
Availability
H

Known Affected Software

30 configuration(s) from 1 vendor(s)

activemq
Version:
5.16.5
CPE:
cpe:2.3:a:apache:activemq:5.16.5:*:*:*:*:*:*:*
activemq
Version:
6.1.0
CPE:
cpe:2.3:a:apache:activemq:6.1.0:*:*:*:*:*:*:*
activemq
Version:
5.16.4
CPE:
cpe:2.3:a:apache:activemq:5.16.4:*:*:*:*:*:*:*
activemq
Version:
5.18.1
CPE:
cpe:2.3:a:apache:activemq:5.18.1:*:*:*:*:*:*:*
activemq
Version:
5.16.1
CPE:
cpe:2.3:a:apache:activemq:5.16.1:*:*:*:*:*:*:*
activemq
Version:
5.16.3
CPE:
cpe:2.3:a:apache:activemq:5.16.3:*:*:*:*:*:*:*
activemq
Version:
6.1.1
CPE:
cpe:2.3:a:apache:activemq:6.1.1:*:*:*:*:*:*:*
activemq
Version:
5.17.5
CPE:
cpe:2.3:a:apache:activemq:5.17.5:*:*:*:*:*:*:*
activemq
Version:
5.18.3
CPE:
cpe:2.3:a:apache:activemq:5.18.3:*:*:*:*:*:*:*
activemq
Version:
6.1.4
CPE:
cpe:2.3:a:apache:activemq:6.1.4:*:*:*:*:*:*:*
activemq
Version:
6.1.5
CPE:
cpe:2.3:a:apache:activemq:6.1.5:*:*:*:*:*:*:*
activemq
Version:
5.16.6
CPE:
cpe:2.3:a:apache:activemq:5.16.6:*:*:*:*:*:*:*
activemq
Version:
5.18.0
CPE:
cpe:2.3:a:apache:activemq:5.18.0:*:*:*:*:*:*:*
activemq
Version:
6.1.3
CPE:
cpe:2.3:a:apache:activemq:6.1.3:*:*:*:*:*:*:*
activemq
Version:
5.17.2
CPE:
cpe:2.3:a:apache:activemq:5.17.2:*:*:*:*:*:*:*
activemq
Version:
5.17.0
CPE:
cpe:2.3:a:apache:activemq:5.17.0:*:*:*:*:*:*:*
activemq
Version:
5.18.4
CPE:
cpe:2.3:a:apache:activemq:5.18.4:*:*:*:*:*:*:*
activemq
Version:
5.17.4
CPE:
cpe:2.3:a:apache:activemq:5.17.4:*:*:*:*:*:*:*
activemq
Version:
6.1.2
CPE:
cpe:2.3:a:apache:activemq:6.1.2:*:*:*:*:*:*:*
activemq
Version:
5.16.2
CPE:
cpe:2.3:a:apache:activemq:5.16.2:*:*:*:*:*:*:*
activemq
Version:
6.0.0
CPE:
cpe:2.3:a:apache:activemq:6.0.0:*:*:*:*:*:*:*
activemq
Version:
5.17.6
CPE:
cpe:2.3:a:apache:activemq:5.17.6:*:*:*:*:*:*:*
activemq
Version:
5.16.0
CPE:
cpe:2.3:a:apache:activemq:5.16.0:*:*:*:*:*:*:*
activemq
Version:
5.17.3
CPE:
cpe:2.3:a:apache:activemq:5.17.3:*:*:*:*:*:*:*
activemq
Version:
5.18.2
CPE:
cpe:2.3:a:apache:activemq:5.18.2:*:*:*:*:*:*:*
activemq
Version:
5.18.5
CPE:
cpe:2.3:a:apache:activemq:5.18.5:*:*:*:*:*:*:*
activemq
Version:
5.16.7
CPE:
cpe:2.3:a:apache:activemq:5.16.7:*:*:*:*:*:*:*
activemq
Version:
5.17.1
CPE:
cpe:2.3:a:apache:activemq:5.17.1:*:*:*:*:*:*:*
activemq
Version:
5.18.6
CPE:
cpe:2.3:a:apache:activemq:5.18.6:*:*:*:*:*:*:*
activemq
Version:
6.0.1
CPE:
cpe:2.3:a:apache:activemq:6.0.1:*:*:*:*:*:*:*
This vulnerability affects 30 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

2 patches available from vendors

View All Patches
Oracle

CPUOCT2025

Oracle Critical Patch Update Advisory - October 2025

Severity
Critical
Released
Oct 21, 2025
Restart Required
Security Update
Oracle

CPUJUL2025

Oracle Critical Patch Update Advisory - July 2025

Severity
Critical
Released
Jul 15, 2025
Restart Required
Security Update

Severity Details

7.5
out of 10.0
High

Key Information

Published Date
May 07, 2025