Impact
An unauthenticated attacker can trigger an Out of Memory condition in the broker by repeatedly sending BrokerInfo commands without first establishing a ConnectionInfo. This leads the broker to consume excessive memory and crash, resulting in a denial of service of the messaging service. The weakness is a form of resource exhaustion denial of service flaw.
Affected Systems
The flaw affects Apache ActiveMQ Broker, Apache ActiveMQ, and Apache ActiveMQ All. Vulnerable releases are 5.19.7 prior to 5.19.8 and 6.2.6 prior to 6.2.7.
Risk and Exploitability
Because no authentication is required, an attacker can cause the broker to consume excessive memory by repeatedly sending BrokerInfo commands without establishing a ConnectionInfo. The attack can be carried out from any host that can reach the broker's OpenWire port. EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is sending crafted OpenWire packets over the network to trigger the memory exhaustion.
OpenCVE Enrichment