Resource exhaustion in ActiveMQ - CVE-2025-27533

 

Resource exhaustion in ActiveMQ - CVE-2025-27533

Published: May 7, 2025 / Updated: May 9, 2025


Vulnerability identifier: #VU108769
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27533
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources during unmarshalling of OpenWire commands. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

ActiveMQ
Jazz for Service Management
Netcool Operations Insight
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
UCD - IBM UrbanCode Deploy
Oracle Communications Session Report Manager
Oracle Enterprise Data Quality
Communications Unified Assurance
RSA Identity Governance and Lifecycle
Oracle Financial Services Analytical Applications Infrastructure
Oracle Communications Element Manager
IBM Cognos Command Center
openEuler
activemq
activemq-javadoc
AMQ Broker

How to mitigate CVE-2025-27533

Install updates from vendor's website.

ActiveMQ - addressed in versions 5.16.8, 5.17.7, 5.18.7, 6.1.6
Jazz for Service Management - update to 1.1.3.25 ifix 0001
Netcool Operations Insight - update to 1.6.15
IBM Tivoli Business Service Manager - update to 7.1.1.0
IBM Tivoli Netcool Impact - update to 7.1.0.37
UCD - IBM UrbanCode Deploy - update to 7.1.2.26
IBM Cognos Command Center - update to 10.2.5 FP1 IF2
activemq - update to 5.16.8-1
activemq-javadoc - update to 5.16.8-1
AMQ Broker - update to 7.13.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins