Improper validation of certificate with host mismatch in ActiveMQ - CVE-2018-11775
Published: September 11, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a MitM attack.
The vulnerability exists due to the Apache ActiveMQ Client does not validate hostname when using SSL/TLS protocol to connect to the Apache ActiveMQ server. A remote attacker can perform a Man-in-the-Middle (MitM) attack and intercept all traffic between Java client and ActiveMQ server.
Affected software
Jazz for Service Management
Enterprise Manager Base Platform
Fuse
IBM Cognos Command Center
Oracle Enterprise Repository
Ubuntu
activemq (Ubuntu package)
libactivemq-java (Ubuntu package)
How to mitigate CVE-2018-11775
Jazz for Service Management - update to 1.1.3.25
Fuse - update to 7.5.0
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF15
activemq (Ubuntu package) - update to Ubuntu Pro
libactivemq-java (Ubuntu package) - update to Ubuntu Pro
External References
Related Security Bulletins
- MitM attack in Apache ActiveMQ Client
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in IBM Cognos Command Center
- Ubuntu update for activemq
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in IBM Jazz for Service Management
- Multiple vulnerabilities in Oracle Enterprise Repository