CVE-2018-11775: Apache ActiveMQ
High severity, CVSS 7.4. EPSS: 7% chance of exploitation in the next 30 days.
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
Affected products
- Apache ActiveMQ: before 5.15.6 (fixed in 5.15.6)
- Oracle Enterprise Repository: version 12.1.3.0.0 only
- Oracle Flexcube Private Banking: version 2.0.0.0 only; version 2.2.0.1 only; version 12.0.1.0 only; version 12.0.3.0 only; version 12.1.0.0 only
Published 2018-09-10. Last modified 2026-06-17.