Medium severity5.9NVD Advisory· Published Sep 10, 2020· Updated Jun 17, 2026
CVE-2020-13920
CVE-2020-13920
Description
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.activemq:activemq-parentMaven | < 5.15.12 | 5.15.12 |
Affected products
8- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*Range: >=8.0.0,<=8.2.2
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
- Apache/ActiveMQdescription
- osv-coords2 versions
< 5.15.12+ 1 more
- (no CPE)range: < 5.15.12
- (no CPE)range: < 5.15.12
Patches
Vulnerability mechanics
References
15- activemq.apache.org/security-advisories.data/CVE-2020-13920-announcement.txtnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-xgrx-xpv2-6vp4ghsaADVISORY
- lists.debian.org/debian-lts-announce/2020/10/msg00013.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-13920ghsaADVISORY
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdThird Party AdvisoryWEB
- github.com/apache/activemq/commit/359ae4bghsaWEB
- github.com/apache/activemq/commit/48cd61dghsaWEB
- github.com/apache/activemq/commit/58382283330f7c7b110c7afd8ef4ca2648786532ghsaWEB
- github.com/apache/activemq/commit/b7dca5eghsaWEB
- issues.apache.org/jira/browse/AMQ-7400ghsaWEB
- lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3EnvdWEB
- lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7@%3Ccommits.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d%40%3Ccommits.activemq.apache.org%3EnvdWEB
- lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d@%3Ccommits.activemq.apache.org%3EghsaWEB
- lists.debian.org/debian-lts-announce/2023/11/msg00013.htmlnvdWEB
News mentions
0No linked articles in our index yet.