<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:06:32 +0000</lastBuildDate>
    <item>
      <title>BIT-activemq-2021-26117 — ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind</title>
      <link>https://cve.radiocsirt.org/vuln/bit-activemq-2021-26117</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-activemq-2021-26117</guid>
    </item>
    <item>
      <title>cnvd-2021-20281</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-20281</link>
      <description>cnvd-2021-20281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-20281</guid>
    </item>
    <item>
      <title>EUVD-2026-24971</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-24971</link>
      <description>EUVD-2026-24971</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-24971</guid>
    </item>
    <item>
      <title>fkie_cve-2021-26117</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-26117</link>
      <description>&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-26117</guid>
    </item>
    <item>
      <title>GHSA-9mgm-gcq8-86wq — Improper Authentication in Apache ActiveMQ and Apache Artemis</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9mgm-gcq8-86wq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-parent, Maven: org.apache.activemq:apache-artemis&lt;/p&gt;
&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-parent, Maven: org.apache.activemq:apache-artemis&lt;/p&gt;
&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9mgm-gcq8-86wq</guid>
    </item>
    <item>
      <title>gsd-2021-26117</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-26117</link>
      <description>gsd-2021-26117</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-26117</guid>
    </item>
    <item>
      <title>RHSA-2020:4154 — Red Hat Security Advisory: Red Hat AMQ Broker 7.4.5 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4154</link>
      <description>&lt;p&gt;Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ hawtio: server side request forgery via initial /proxy/ substring of a URI activemq: LDAP authentication bypass with anonymous bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ hawtio: server side request forgery via initial /proxy/ substring of a URI activemq: LDAP authentication bypass with anonymous bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4154</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-26117</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26117</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26117</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1807 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</guid>
    </item>
  </channel>
</rss>
