TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2018-09-10 20:29
Updated : 2024-11-21 03:44
NVD link : CVE-2018-11775
Mitre link : CVE-2018-11775
CVE.ORG link : CVE-2018-11775
JSON object : View
Products Affected
oracle
- flexcube_private_banking
- enterprise_repository
apache
- activemq
CWE
CWE-295
Improper Certificate Validation