Impact
The description indicates that unsafe parsing permits a remote attacker to read arbitrary files from the MQ Broker’s server. It is inferred that the vulnerability involves a path traversal flaw, as it allows access to files outside the intended configuration directory, yet the description does not explicitly state this. In some scenarios remote code execution may also be achieved.
Affected Systems
The affected products are Eclipse OpenMQ and Eclipse GlassFish. Versions of OpenMQ prior to 6.5.2 and 6.9.0, and GlassFish versions prior to 7.0.26, 7.1.1, and 8.0.2, are vulnerable. Deployment using any of these products should verify the installed version and apply the vendor’s fixes.
Risk and Exploitability
With a CVSS score of 9.1, this is a severe vulnerability. The EPSS score of less than 1% suggests a low current exploitation probability, and it is not listed in the CISA KEV catalog. The likely attack vector is remote, inferred from the ability to send crafted configuration data to the broker; the description does not explicitly state how the configuration interface is exposed. If such an attack can be carried out, the attacker could read arbitrary files or potentially execute code depending on the system.
OpenCVE Enrichment