<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:08:23.542466+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-activemq-2021-26117</id>
    <title>BIT-activemq-2021-26117 — ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind</title>
    <updated>2026-10-04T07:08:23.658345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: activemq</p>
<p>The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-activemq-2021-26117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-20281</id>
    <title>cnvd-2021-20281</title>
    <updated>2026-10-04T07:08:23.658407+00:00</updated>
    <content>cnvd-2021-20281</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-20281"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-24971</id>
    <title>EUVD-2026-24971</title>
    <updated>2026-10-04T07:08:23.658425+00:00</updated>
    <content>EUVD-2026-24971</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-24971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-26117</id>
    <title>fkie_cve-2021-26117</title>
    <updated>2026-10-04T07:08:23.658437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-26117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9mgm-gcq8-86wq</id>
    <title>GHSA-9mgm-gcq8-86wq — Improper Authentication in Apache ActiveMQ and Apache Artemis</title>
    <updated>2026-10-04T07:08:23.658461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.activemq:activemq-parent, Maven: org.apache.activemq:apache-artemis</p>
<p>The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9mgm-gcq8-86wq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-26117</id>
    <title>gsd-2021-26117</title>
    <updated>2026-10-04T07:08:23.658486+00:00</updated>
    <content>gsd-2021-26117</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-26117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:4154</id>
    <title>RHSA-2020:4154 — Red Hat Security Advisory: Red Hat AMQ Broker 7.4.5 release and security update</title>
    <updated>2026-10-04T07:08:23.658498+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ hawtio: server side request forgery via initial /proxy/ substring of a URI activemq: LDAP authentication bypass with anonymous bind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:4154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26117</id>
    <title>UBUNTU-CVE-2021-26117</title>
    <updated>2026-10-04T07:08:23.658519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq</p>
<p>The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</id>
    <title>WID-SEC-W-2023-1807 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
    <updated>2026-10-04T07:08:23.658541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807"/>
  </entry>
</feed>
