WORLDTECH NEWS Global technology intelligence.Contact
โ† Back to WORLDTECH

Hitachi Energy SOI

Close-up of a surveillance camera on a pole under a clear blue sky.
Illustrative photo.Photo by Ilman Muhammad on Pexels

What happened

These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, integrity, and availability of the product. View CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document.

Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console.

The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.

Sources & evidence