3
Total CVEs
0
Critical
2
High
1
Medium
0
Low

Recent CVEs

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bri...

Affected versions: 1.1 1.2 1.3 1.4 1.5 +107 more

Published: Apr 7, 2026

8.8

CVSS

WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq.apache.org/security-advisories.data/CVE...

Affected versions: 1.1 1.2 1.3 1.4 1.5 +107 more

Published: Mar 4, 2026

5.4

CVSS

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excess...

Affected versions: 5.16.0 5.16.1 5.16.2 5.16.3 5.16.4 +25 more

Published: May 7, 2025

7.5

CVSS

In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers wi...

Affected versions: 6.0.0 6.0.1 6.1.0 6.1.1

Published: May 2, 2024

8.5

CVSS

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and r...

Affected versions: 5.15.9

Published: May 23, 2019

5.9

CVSS

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input...

Affected versions: 5.15.8

Published: May 15, 2019

9.8

CVSS

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServl...

Affected versions: 5.15.9

Published: Apr 22, 2019

6.1

CVSS

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper...

Affected versions: 5.0.0 5.1.0 5.10.0 5.10.1 5.10.2 +31 more

Published: Jan 10, 2018

4.3

CVSS

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML message...

Affected versions: 5.0.0 5.1.0 5.10.0 5.2.0 5.3.0 +13 more

Published: Oct 27, 2017

7.5

CVSS

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and ...

Affected versions: 5.1.0 5.10.0 5.10.1 5.10.2 5.11.0 +23 more

Published: Aug 5, 2016

3.5

CVSS

CVE-2016-3088 KEV Exploit

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request....

Affected versions: 5.0.0 5.1.0 5.10.0 5.10.1 5.10.2 +29 more

Published: Jun 1, 2016

9.8

CVSS

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a...

Affected versions: 5.0.0 5.1.0 5.10.0 5.10.1 5.10.2 +22 more

Published: Apr 7, 2016

4.3

CVSS

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Serv...

Affected versions: 5.0.0 5.1.0 5.10.0 5.10.1 5.10.2 +19 more

Published: Jan 8, 2016

7.5

CVSS

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attacker...

Affected versions: 5.0.0 5.1.0 5.10.0 5.2.0 5.3.0 +13 more

Published: Aug 24, 2015

5.0

CVSS

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with ...

Affected versions: 5.0.0 5.1.0 5.10.0 5.2.0 5.3.0 +13 more

Published: Aug 24, 2015

7.5

CVSS

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbi...

Affected versions: 5.0.0 5.1.0 5.10.0 5.10.1 5.10.2 +17 more

Published: Aug 19, 2015

5.0

CVSS

The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command....

Affected versions: 1.1 1.2 1.3 1.4 1.5 +31 more

Published: Aug 14, 2015

5.0

CVSS

Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspe...

Affected versions: 5.0.0 5.1.0 5.10.0 5.2.0 5.3.0 +13 more

Published: Feb 12, 2015

4.3

CVSS

Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML v...

Affected versions: 5.0.0 5.1.0 5.2.0 5.3.0 5.3.1 +8 more

Published: Feb 5, 2014

4.3

CVSS

Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a messa...

Affected versions: 1.1 1.2 1.3 1.4 1.5 +28 more

Published: Jul 20, 2013

4.3

CVSS

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests....

Affected versions: 1.1 1.2 1.3 1.4 1.5 +27 more

Published: Apr 21, 2013

6.4

CVSS

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests....

Affected versions: 1.1 1.2 1.3 1.4 1.5 +27 more

Published: Apr 21, 2013

5.0

CVSS

Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to Port...

Affected versions: 1.1 1.2 1.3 1.4 1.5 +27 more

Published: Apr 21, 2013

4.3

CVSS

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, doe...

Affected versions: 1.1 1.2 1.3 1.4 1.5 +27 more

Published: Nov 4, 2012

5.8

CVSS

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests....

Affected versions: 1.1 1.2 1.3 1.4 1.5 +24 more

Published: Jan 5, 2012

5.0

CVSS

The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/ind...

Affected versions: 5.0.0 5.1.0 5.2.0 5.3.0 5.3.1 +1 more

Published: Apr 28, 2010

5.0

CVSS

Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests tha...

Affected versions: 1.1 1.2 1.3 1.4 1.5 +17 more

Published: Apr 5, 2010

6.8

CVSS

Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination par...

Affected versions: 1.1 1.2 1.3 1.4 1.5 +17 more

Published: Apr 5, 2010

3.5

CVSS