VYPR
High severity7.4NVD Advisory· Published Sep 10, 2018· Updated Jun 17, 2026

CVE-2018-11775

CVE-2018-11775

Description

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.activemq:activemq-clientMaven
< 5.15.65.15.6

Affected products

9
  • Apache/Activemq2 versions
    cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*range: <5.15.6
    • (no CPE)range: 5.0.0 - 5.15.5
  • cpe:2.3:a:oracle:enterprise_repository:12.1.3.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:flexcube_private_banking:12.0.1.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:oracle:flexcube_private_banking:12.0.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:flexcube_private_banking:12.0.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:flexcube_private_banking:12.1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:flexcube_private_banking:2.0.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:flexcube_private_banking:2.2.0.1:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

25

News mentions

0

No linked articles in our index yet.