CVE-2019-0222: Apache ActiveMQ

High severity, CVSS 7.5. EPSS: 12% chance of exploitation in the next 30 days.

In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

Affected products

  • Apache ActiveMQ: from 5.0.0, up to and including 5.15.8
  • Debian Debian Linux: version 9.0 only
  • Netapp E-Series Santricity Web Services: affected versions not specified
  • Oracle Communications Diameter Signaling Router: version 8.0.0 only; version 8.1 only; version 8.2 only; version 8.2.1 only
  • Oracle Enterprise Manager Base Platform: version 12.1.0.5.0 only; version 13.2.0.0.0 only; version 13.3.0.0.0 only
  • Oracle Enterprise Repository: version 12.1.3.0.0 only
  • Oracle Goldengate Stream Analytics: before 19.1.0.0.1 (fixed in 19.1.0.0.1)
  • Oracle Identity Manager Connector: version 9.0 only

Published 2019-03-28. Last modified 2026-06-17.