CVE-2020-13931

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2020
Last modified:
07/11/2023

Description

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:* 1.0.0 (including) 1.7.5 (including)
cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.8 (including)
cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:* 7.1.0 (including) 7.1.3 (including)
cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.3 (including)
cpe:2.3:a:apache:tomee:7.0.0:m1:*:*:*:*:*:*
cpe:2.3:a:apache:tomee:7.0.0:m2:*:*:*:*:*:*
cpe:2.3:a:apache:tomee:7.0.0:m3:*:*:*:*:*:*
cpe:2.3:a:apache:tomee:8.0.0:m1:*:*:*:*:*:*