activemq: Unauthenticated access to web console
Published Apr 21, 2013
6.4
MEDIUMCVSS 2.0
EPSS 6.31%
Description
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
Affected products
No data.
- ≤ 5.7.0
- 4.0
- 4.0
- 4.0
- 4.0.1
- 4.0.2
- 4.1.0
- 4.1.1
- 5.0.0
- 5.1.0
- 5.2.0
- 5.3.0
- 5.3.1
- 5.3.2
- 5.4.0
- 5.4.1
- 5.4.2
- 5.5.0
- 5.5.1
- 5.6.0
No data.
Fuse MQ Enterprise 7.1.0
n/a
Fixed · RHSA-2013:1029
Fuse Message Broker 5.5.1
n/a
Fixed · RHSA-2013:1221
OpenShift Enterprise 1
activemq
Affected
Red Hat JBoss SOA Platform 4
activemq
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Fuse MQ Enterprise 7.1.0 | n/a | Fixed | RHSA-2013:1029 |
| Fuse Message Broker 5.5.1 | n/a | Fixed | RHSA-2013:1221 |
| OpenShift Enterprise 1 | activemq | Affected | n/a |
| Red Hat JBoss SOA Platform 4 | activemq | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Fuse ESB Enterprise 7.1.0, Fuse MQ Enterprise 7.1.1, JBoss Fuse 6.0.0 and JBoss A-MQ 6.0.0 all contain the Apache ActiveMQ web console, but it is not deployed by default. The documentation for deploying the web console covers the configuration needed to ensure authentication is enabled, therefore these products are not affected by this flaw. In a future update to these products, the web console will be configured so that authentication is automatically enabled if the web console is deployed, eliminating the need to manually configure it. A future update may address this flaw in Fuse Message Broker 5.5.1.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 6.31% (0.06311) | 93.41th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.26% (0.06257) | 92.63th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.02% (0.01019) | 75.21th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.61% (0.02608) | 76.04th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.02% (0.01019) | 75.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.46% (0.00459) | 76.16th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.46% (0.00459) | 74.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.46% (0.00459) | 71.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.21% (0.02210) | 81.16th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.21% (0.02210) | 79.37th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.21% (0.02210) | 58.05th | v2 (v2022.01.01) |
References (16)
- http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.html mailing-listx_refsource_MLIST
- http://activemq.apache.org/activemq-580-release.html x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2013-1029.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1221.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/59402 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-3060 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=955908 Issue Tracking
- https://fisheye6.atlassian.com/changelog/activemq?cs=1404998 x_refsource_CONFIRM
- https://github.com/advisories/GHSA-p358-58jj-hp65 Advisory
- https://github.com/apache/activemq/commit/22bc55b9487df98a3c3cb04f99f4618fcba364fe
- https://github.com/apache/activemq/commit/437ea2f6e58d18837ae0e68dcd2fdadc1fff3723
- https://github.com/apache/activemq/commit/ced33d2551a040813cb40bd6d36fdd322034fa73
- https://issues.apache.org/jira/browse/AMQ-4124 x_refsource_CONFIRM
- https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2013-3060
- https://www.cve.org/CVERecord?id=CVE-2013-3060
Change history (0)
No recorded changes yet.