Improper validation of certificate with host mismatch in ActiveMQ - CVE-2018-11775

 

Improper validation of certificate with host mismatch in ActiveMQ - CVE-2018-11775

Published: September 11, 2018


Vulnerability identifier: #VU14741
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11775
CWE-ID: CWE-297
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a MitM attack.

The vulnerability exists due to the Apache ActiveMQ Client does not validate hostname when using SSL/TLS protocol to connect to the Apache ActiveMQ server. A remote attacker can perform a Man-in-the-Middle (MitM) attack and intercept all traffic between Java client and ActiveMQ server.


Affected software

ActiveMQ
Jazz for Service Management
Enterprise Manager Base Platform
Fuse
IBM Cognos Command Center
Oracle Enterprise Repository
Ubuntu
activemq (Ubuntu package)
libactivemq-java (Ubuntu package)

How to mitigate CVE-2018-11775

Update to version5.5.16.

ActiveMQ - update to 5.15.6
Jazz for Service Management - update to 1.1.3.25
Fuse - update to 7.5.0
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF15
activemq (Ubuntu package) - update to Ubuntu Pro
libactivemq-java (Ubuntu package) - update to Ubuntu Pro

External References

Related Security Bulletins