Resource exhaustion in ActiveMQ - CVE-2025-27533
Published: May 7, 2025 / Updated: May 9, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources during unmarshalling of OpenWire commands. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Jazz for Service Management
Netcool Operations Insight
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
UCD - IBM UrbanCode Deploy
Oracle Communications Session Report Manager
Oracle Enterprise Data Quality
Communications Unified Assurance
RSA Identity Governance and Lifecycle
Oracle Financial Services Analytical Applications Infrastructure
Oracle Communications Element Manager
IBM Cognos Command Center
openEuler
activemq
activemq-javadoc
AMQ Broker
How to mitigate CVE-2025-27533
Jazz for Service Management - update to 1.1.3.25 ifix 0001
Netcool Operations Insight - update to 1.6.15
IBM Tivoli Business Service Manager - update to 7.1.1.0
IBM Tivoli Netcool Impact - update to 7.1.0.37
UCD - IBM UrbanCode Deploy - update to 7.1.2.26
IBM Cognos Command Center - update to 10.2.5 FP1 IF2
activemq - update to 5.16.8-1
activemq-javadoc - update to 5.16.8-1
AMQ Broker - update to 7.13.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in Apache ActiveMQ
- openEuler update for activemq
- IBM Jazz for Service Management update for Apache ActiveMQ
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure
- IBM DevOps Deploy update for Apache ActiveMQ
- Multiple vulnerabilities in AMQ Broker 7.13
- Multiple Apache ActiveMQ vulnerabilities in RSA Governance and Lifecycle
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Enterprise Data Quality
- Multiple vulnerabilities in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in IBM Cognos Command Center