CVE-2020-13947: Apache ActiveMQ

Medium severity, CVSS 6.1. EPSS: 79% chance of exploitation in the next 30 days.

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

Affected products

  • Apache ActiveMQ: before 5.15.14 (fixed in 5.15.14); from 5.16.0, before 5.16.1 (fixed in 5.16.1)
  • Oracle Communications Session Report Manager: from 8.0.0, up to and including 8.2.2
  • Oracle Communications Session Route Manager: from 8.0.0, up to and including 8.2.2

Published 2021-02-08. Last modified 2026-06-17.