Impact
Missing authorization in Apache ActiveMQ Classic creates a scenario where temporary destinations, which are meant to be isolated to the client that created them, can be accessed by any other connected client. An attacker who establishes a separate connection to the broker can consume messages from another connection's temporary destination, enabling unauthorized read of potentially confidential messages. The weakness is a classic lack of access control (CWE‑1220) and missing authorization checks (CWE‑862).
Affected Systems
This issue affects Apache ActiveMQ Classic, Broker, and All editions before 5.19.8 and any 6.x release prior to 6.2.7. Users running those versions are vulnerable. The vendor recommends upgrading to at least 5.19.8 for the 5.x line or 6.2.7 for the 6.x line.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability, and the EPSS score is not available, so the likelihood of exploitation is uncertain but not negligible. Because the flaw requires the attacker to possess a separate connection to the broker, environments with weak authentication or internal network exposure could provide the necessary prerequisites. The vulnerability is not listed in CISA KEV, and no public exploits are known as of the data, but the potential impact of unauthorized data access warrants immediate remediation.
OpenCVE Enrichment