TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2018-09-10 13:29
Updated : 2021-03-05 11:15
NVD link : CVE-2018-11775
Mitre link : CVE-2018-11775
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
oracle
- enterprise_repository
- flexcube_private_banking
apache
- activemq