« Volver al listado

CVE-2020-13931

Estado: ModificadaCrítica (9.8)—

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-13931",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Apache TomEE",
          "versions": [
            {
              "status": "affected",
              "version": "Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-18T00:15:14.190",
  "references": [
    {
      "url": "https://lists.apache.org/thread.html/r7f98907165b355dc65f28a57f15103a06173ce03261115fa46d569b4%40%3Cdev.tomee.apache.org%3E",
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r85b87478f8aa4751aa3a06e88622e80ffabae376ee7283e147ee56b9%40%3Cdev.tomee.apache.org%3E",
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/ref088c4732e1a8dd0bbbb96e13ffafcfe65f984238ffa55f438d78fe%40%3Cdev.tomee.apache.org%3E",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r7f98907165b355dc65f28a57f15103a06173ce03261115fa46d569b4%40%3Cdev.tomee.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r85b87478f8aa4751aa3a06e88622e80ffabae376ee7283e147ee56b9%40%3Cdev.tomee.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/ref088c4732e1a8dd0bbbb96e13ffafcfe65f984238ffa55f438d78fe%40%3Cdev.tomee.apache.org%3E",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case."
    },
    {
      "lang": "es",
      "value": "Si Apache TomEE versiones 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 está configurado para utilizar el broker ActiveMQ insertado y el broker config está configurado inapropiadamente, un puerto JMX es abierto en el puerto TCP 1099, que no incluye autenticación. CVE-2020-11969 abordó previamente la creación de la interfaz de administración JMX, sin embargo, una corrección incompleta no cubrió este caso extremo"
    }
  ],
  "lastModified": "2026-06-17T02:53:55.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9836083A-FD7C-4E1B-91B1-7E41933345F1",
              "versionEndIncluding": "1.7.5",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6443620-3F4B-4AFE-926F-86FC3E2F3CDA",
              "versionEndIncluding": "7.0.8",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C6DCBEB-07E1-486B-8E2B-661E2BC48814",
              "versionEndIncluding": "7.1.3",
              "versionStartIncluding": "7.1.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCDB6F9A-F6DB-418A-A113-E440EFBF9F42",
              "versionEndIncluding": "8.0.3",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomee:7.0.0:m1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF7BA078-B944-4A03-BC12-2DB95BD474A3"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomee:7.0.0:m2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E520207-5DC0-4B93-8A66-D9396EB64559"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomee:7.0.0:m3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19027673-1DF2-47D6-90F2-FD59DD2E690B"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomee:8.0.0:m1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AADB1D64-64A7-44C8-B433-550AA6A0E6A8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}