Missing authorization in ActiveMQ - CVE-2024-32114
Published: May 1, 2024
Vulnerability identifier: #VU89096
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-32114
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to missing authorization in the application's REST API. A remote attacker can interact with the broker using Jolokia JMX REST API and produce/consume messages or purge/delete destinations using the Message REST API.
Affected software
ActiveMQ
Oracle Financial Services Analytical Applications Infrastructure
Oracle Banking Digital Experience
Oracle Banking APIs
Oracle Financial Services Analytical Applications Infrastructure
Oracle Banking Digital Experience
Oracle Banking APIs
How to mitigate CVE-2024-32114
Install updates from vendor's website.
ActiveMQ - update to 6.1.2