CVE-2017-15709: Apache ActiveMQ

Low severity, CVSS 3.7. EPSS: 22.8% chance of exploitation in the next 30 days.

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

Affected products

  • Apache ActiveMQ: from 5.14.0, up to and including 5.15.2

Published 2018-02-13. Last modified 2026-06-17.