The vendor explicitly identifies these products as affected by this CVE.
- activemq-artemis-native as a component of Red Hat AMQ Broker 7
- activemq-client as a component of Red Hat AMQ Broker 7
- activemq-openwire-legacy as a component of Red Hat AMQ Broker 7
- apache-artemis as a component of Red Hat AMQ Broker 7
- artemis-amqp-protocol as a component of Red Hat AMQ Broker 7
- artemis-boot as a component of Red Hat AMQ Broker 7
- artemis-cli as a component of Red Hat AMQ Broker 7
- artemis-commons as a component of Red Hat AMQ Broker 7
- artemis-console as a component of Red Hat AMQ Broker 7
- artemis-console-war as a component of Red Hat AMQ Broker 7
- artemis-core-client as a component of Red Hat AMQ Broker 7
- artemis-dto as a component of Red Hat AMQ Broker 7
- Summary
- A flaw was found in Apache ActiveMQ. A remote, unauthenticated attacker can exploit an improper input validation vulnerability by sending a specially crafted message with a negative content-length to an exposed STOMP connector. This can lead to a denial of service (DoS) condition, either by consuming excessive memory and causing an Out-Of-Memory (OOM) error or by forcing the abnormal closure of affected connections.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).
