Impact
The vulnerability in Apache ActiveMQ allows an unauthenticated attacker to retrieve a detailed list of all durable topic subscriptions from the broker. By sending a BrokerInfo command, the broker responds with client identifiers, subscription names, topic destinations, and JMS selector expressions without first authenticating the connection.
Affected Systems
Apache Software Foundation products – Apache ActiveMQ, Apache ActiveMQ All, and Apache ActiveMQ Broker – are affected. Versions prior to 5.19.7 and the range from 6.0.0 up to but not including 6.2.6 receive the insecure behavior.
Risk and Exploitability
The flaw exposes sensitive configuration data without requiring authentication; however, the EPSS score of <1% suggests a low probability of exploitation over the network. The CVSS score of 5.9 indicates moderate severity, and the vulnerability is not yet listed in CISA KEV.
OpenCVE Enrichment