// For flags

CVE-2019-0222

activemq: Corrupt MQTT frame can cause broker shutdown

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

En Apache ActiveMQ, desde la versión 5.0.0 hasta la 5.15.8, la deserialización de una trama MQTT corrupta puede conducir a una excepción de bróker fuera de memoria, haciendo que no responda.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-11-14 CVE Reserved
  • 2019-03-28 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-18 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (21)
URL Tag Source
http://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.txt Mitigation
http://www.openwall.com/lists/oss-security/2019/03/27/2 Mailing List
http://www.securityfocus.com/bid/107622 Third Party Advisory
https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1%40%3Cdev.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc%40%3Ccommits.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4b8cddc4f8d485%40%3Cdev.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d925218b5774622f488%40%3Cusers.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302f9c1feed087fa%40%3Ccommits.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b%40%3Cdev.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675ea1ef402e04a6d%40%3Ccommits.activemq.apache.org%3E Mailing List
https://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3E Mailing List
https://lists.debian.org/debian-lts-announce/2021/03/msg00004.html Mailing List
https://lists.debian.org/debian-lts-announce/2021/03/msg00005.html Mailing List
https://security.netapp.com/advisory/ntap-20190502-0006 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html Third Party Advisory
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Activemq
Search vendor "Apache" for product "Activemq"
>= 5.0.0 <= 5.15.8
Search vendor "Apache" for product "Activemq" and version " >= 5.0.0 <= 5.15.8"
-
Affected
Netapp
Search vendor "Netapp"
E-series Santricity Web Services
Search vendor "Netapp" for product "E-series Santricity Web Services"
--
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
8.0.0
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version "8.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
8.1
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version "8.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
8.2
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version "8.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
8.2.1
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version "8.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
12.1.0.5.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "12.1.0.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.2.0.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.2.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.3.0.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.3.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Repository
Search vendor "Oracle" for product "Enterprise Repository"
12.1.3.0.0
Search vendor "Oracle" for product "Enterprise Repository" and version "12.1.3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate Stream Analytics
Search vendor "Oracle" for product "Goldengate Stream Analytics"
< 19.1.0.0.1
Search vendor "Oracle" for product "Goldengate Stream Analytics" and version " < 19.1.0.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Identity Manager Connector
Search vendor "Oracle" for product "Identity Manager Connector"
9.0
Search vendor "Oracle" for product "Identity Manager Connector" and version "9.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected