Resource exhaustion in ActiveMQ - CVE-2019-0222

 

Resource exhaustion in ActiveMQ - CVE-2019-0222

Published: July 22, 2019


Vulnerability identifier: #VU19300
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0222
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error when processing corrupt MQTT frames. A remote attacker can consume all memory resources on the system and perform a denial of service (DoS) attack.


Affected software

ActiveMQ
Jazz for Service Management
Oracle Communications Diameter Signaling Router (DSR)
Enterprise Manager Base Platform
AMQ Broker
Identity Manager Connector
Oracle Enterprise Repository
Stream Analytics
Ubuntu
libmqtt-client-java (Ubuntu package)

How to mitigate CVE-2019-0222

Install updates from vendor's website.

ActiveMQ - update to 5.15.9
Jazz for Service Management - update to 1.1.3.25
AMQ Broker - addressed in versions 7.4.3, 7.6
Stream Analytics - update to 19.1.0.0.1
libmqtt-client-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.14-1+deb10u1build0.20.04.1

External References

Related Security Bulletins