CVE-2015-7559: Apache ActiveMQ

Low severity, CVSS 2.7. EPSS: 2% chance of exploitation in the next 30 days.

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

Affected products

  • Apache ActiveMQ: before 5.14.5 (fixed in 5.14.5); from 5.15.0, before 5.15.5 (fixed in 5.15.5)
  • Red Hat JBoss A-Mq: version 6.2.1 only; version 6.3 only
  • Red Hat JBoss Fuse: version 6.3 only

Published 2019-08-01. Last modified 2026-06-17.