Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement. In real-world deployments, this service is often left enabled without changing the default credentials. As a result, a remote attacker with access to the service port could authenticate as an administrator and gain full control of the protocol’s administrative features.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1392
Vulnerability Title
OpenMQ 安全漏洞
Vulnerability Description
OpenMQ是Java EE开源的一个消息流中间件。 OpenMQ存在安全漏洞,该漏洞源于默认使用管理员凭据且未强制首次使用时更改密码,可能导致远程攻击者以管理员身份认证并获得完全控制。
CVSS Information
N/A
Vulnerability Type
N/A