Description
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 – 8.0.1, Apache TomEE 7.1.0 – 7.1.2, Apache TomEE 7.0.0-M1 – 7.0.7, Apache TomEE 1.0.0 – 1.7.5.
Mitigation
We recommend upgrading to a version of this component that is not vulnerable to this specific issue.
"Alternatively, users may wish to remove the `useJMX` option from the URI (the default is `false`)."
Reference: [https://lists.apache.org/thread.html/rbd23418646dedda70a546331ea1c1d115b8975b7e7dc452d10e2e773%40%3Cdev.tomee.apache.org%3E](https://lists.apache.org/thread.html/rbd23418646dedda70a546331ea1c1d115b8975b7e7dc452d10e2e773%40%3Cdev.tomee.apache.org%3E)
Note: If this component is included as a bundled/transitive dependency of another component, there may not be an upgrade path. In this instance, we recommend contacting the maintainers who included the vulnerable package. Alternatively, we recommend investigating alternative components or a potential mitigating control.