{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34197.json"
      }
    ],
    "title": "org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: RCE via crafted discovery URI in Jolokia JMX-HTTP bridge",
    "tracking": {
      "current_release_date": "2026-06-28T07:30:58+00:00",
      "generator": {
        "date": "2026-06-28T07:30:58+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.2.6"
        }
      },
      "id": "CVE-2026-34197",
      "initial_release_date": "2026-04-07T07:50:10.958000+00:00",
      "revision_history": [
        {
          "date": "2026-04-07T07:50:10.958000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-21T16:37:00+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-28T07:30:58+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat AMQ Broker 7",
                "product": {
                  "name": "Red Hat AMQ Broker 7",
                  "product_id": "red_hat_amq_broker_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:amq_broker:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat AMQ Broker 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Data Grid 8",
                "product": {
                  "name": "Red Hat Data Grid 8",
                  "product_id": "red_hat_data_grid_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_data_grid:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Data Grid 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 8",
                "product": {
                  "name": "Red Hat Enterprise Linux 8",
                  "product_id": "red_hat_enterprise_linux_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 9",
                "product": {
                  "name": "Red Hat Enterprise Linux 9",
                  "product_id": "red_hat_enterprise_linux_9",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:9"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 9"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Fuse 7",
                "product": {
                  "name": "Red Hat Fuse 7",
                  "product_id": "red_hat_fuse_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Fuse 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 7",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 7",
                  "product_id": "red_hat_jboss_enterprise_application_platform_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 8",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 8",
                  "product_id": "red_hat_jboss_enterprise_application_platform_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                  "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jbosseapxp"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "category": "product_version",
            "name": "activemq-broker",
            "product": {
              "name": "activemq-broker",
              "product_id": "activemq-broker",
              "product_identification_helper": {
                "purl": "pkg:maven/org.apache.activemq/activemq-broker"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j-slf4j",
            "product": {
              "name": "log4j-slf4j",
              "product_id": "log4j-slf4j",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j-slf4j?rpmmod=log4j:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j",
            "product": {
              "name": "log4j",
              "product_id": "log4j",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j?rpmmod=log4j:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j-jcl",
            "product": {
              "name": "log4j-jcl",
              "product_id": "log4j-jcl",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j-jcl?rpmmod=log4j:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j-web",
            "product": {
              "name": "log4j-web",
              "product_id": "log4j-web",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j-web?rpmmod=log4j:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "log4j.src",
            "product": {
              "name": "log4j.src",
              "product_id": "log4j.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/log4j?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "activemq-all",
            "product": {
              "name": "activemq-all",
              "product_id": "activemq-all",
              "product_identification_helper": {
                "purl": "pkg:maven/org.apache.activemq/activemq-all"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "activemq-broker as a component of Red Hat AMQ Broker 7",
          "product_id": "red_hat_amq_broker_7:activemq-broker"
        },
        "product_reference": "activemq-broker",
        "relates_to_product_reference": "red_hat_amq_broker_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "activemq-broker as a component of Red Hat Data Grid 8",
          "product_id": "red_hat_data_grid_8:activemq-broker"
        },
        "product_reference": "activemq-broker",
        "relates_to_product_reference": "red_hat_data_grid_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:log4j"
        },
        "product_reference": "log4j",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-jcl as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:log4j-jcl"
        },
        "product_reference": "log4j-jcl",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-slf4j as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:log4j-slf4j"
        },
        "product_reference": "log4j-slf4j",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-web as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:log4j-web"
        },
        "product_reference": "log4j-web",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-jcl as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:log4j-jcl"
        },
        "product_reference": "log4j-jcl",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j-slf4j as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:log4j-slf4j"
        },
        "product_reference": "log4j-slf4j",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "log4j.src as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:log4j.src"
        },
        "product_reference": "log4j.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "activemq-all as a component of Red Hat Fuse 7",
          "product_id": "red_hat_fuse_7:activemq-all"
        },
        "product_reference": "activemq-all",
        "relates_to_product_reference": "red_hat_fuse_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "activemq-broker as a component of Red Hat Fuse 7",
          "product_id": "red_hat_fuse_7:activemq-broker"
        },
        "product_reference": "activemq-broker",
        "relates_to_product_reference": "red_hat_fuse_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "activemq-broker as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:activemq-broker"
        },
        "product_reference": "activemq-broker",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "activemq-broker as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:activemq-broker"
        },
        "product_reference": "activemq-broker",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "activemq-broker as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:activemq-broker"
        },
        "product_reference": "activemq-broker",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-34197",
      "cwe": {
        "id": "CWE-78",
        "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
      },
      "discovery_date": "2026-04-07T09:01:09.089480+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "red_hat_amq_broker_7:activemq-broker"
          ]
        },
        {
          "label": "component_not_present",
          "product_ids": [
            "red_hat_data_grid_8:activemq-broker"
          ]
        },
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_enterprise_linux_8:log4j",
            "red_hat_enterprise_linux_8:log4j-jcl",
            "red_hat_enterprise_linux_8:log4j-slf4j",
            "red_hat_enterprise_linux_8:log4j-web",
            "red_hat_enterprise_linux_9:log4j-jcl",
            "red_hat_enterprise_linux_9:log4j-slf4j",
            "red_hat_enterprise_linux_9:log4j.src",
            "red_hat_fuse_7:activemq-all",
            "red_hat_fuse_7:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_7:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_8:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:activemq-broker"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2455869"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache ActiveMQ Broker and Apache ActiveMQ. An authenticated attacker can exploit this vulnerability by sending a specially crafted discovery Uniform Resource Identifier (URI) to the Jolokia JMX-HTTP bridge, which is exposed on the web console. This allows the attacker to bypass configuration validation and load a remote Spring XML application context. Consequently, this leads to arbitrary code execution on the broker's Java Virtual Machine (JVM).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: RCE via crafted discovery URI in Jolokia JMX-HTTP bridge",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an Important severity flaw as it could enable a remote, authenticated attacker to execute arbitrary code on the broker's JVM. This can be exploited by sending a specially crafted discovery URI to the Jolokia JMX-HTTP bridge, which is exposed on the web console. This bypasses configuration validation and allows loading a remote Spring XML application context.\n\nThe vulnerable components are used strictly at build time or for internal testing and are not included in shipped products. Consequently, Red Hat products are marked as unaffected.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_amq_broker_7:activemq-broker",
          "red_hat_data_grid_8:activemq-broker",
          "red_hat_enterprise_linux_8:log4j",
          "red_hat_enterprise_linux_8:log4j-jcl",
          "red_hat_enterprise_linux_8:log4j-slf4j",
          "red_hat_enterprise_linux_8:log4j-web",
          "red_hat_enterprise_linux_9:log4j-jcl",
          "red_hat_enterprise_linux_9:log4j-slf4j",
          "red_hat_enterprise_linux_9:log4j.src",
          "red_hat_fuse_7:activemq-all",
          "red_hat_fuse_7:activemq-broker",
          "red_hat_jboss_enterprise_application_platform_7:activemq-broker",
          "red_hat_jboss_enterprise_application_platform_8:activemq-broker",
          "red_hat_jboss_enterprise_application_platform_expansion_pack:activemq-broker"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-34197"
        },
        {
          "category": "external",
          "summary": "RHBZ#2455869",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455869"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-34197",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34197"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-34197",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34197"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/06/3",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/06/3"
        },
        {
          "category": "external",
          "summary": "https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt",
          "url": "https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "release_date": "2026-04-07T07:50:10.958000+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_amq_broker_7:activemq-broker",
            "red_hat_data_grid_8:activemq-broker",
            "red_hat_enterprise_linux_8:log4j",
            "red_hat_enterprise_linux_8:log4j-jcl",
            "red_hat_enterprise_linux_8:log4j-slf4j",
            "red_hat_enterprise_linux_8:log4j-web",
            "red_hat_enterprise_linux_9:log4j-jcl",
            "red_hat_enterprise_linux_9:log4j-slf4j",
            "red_hat_enterprise_linux_9:log4j.src",
            "red_hat_fuse_7:activemq-all",
            "red_hat_fuse_7:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_7:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_8:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:activemq-broker"
          ]
        }
      ],
      "threats": [
        {
          "category": "exploit_status",
          "date": "2026-04-16T00:00:00+00:00",
          "details": "CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_amq_broker_7:activemq-broker",
            "red_hat_data_grid_8:activemq-broker",
            "red_hat_enterprise_linux_8:log4j",
            "red_hat_enterprise_linux_8:log4j-jcl",
            "red_hat_enterprise_linux_8:log4j-slf4j",
            "red_hat_enterprise_linux_8:log4j-web",
            "red_hat_enterprise_linux_9:log4j-jcl",
            "red_hat_enterprise_linux_9:log4j-slf4j",
            "red_hat_enterprise_linux_9:log4j.src",
            "red_hat_fuse_7:activemq-all",
            "red_hat_fuse_7:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_7:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_8:activemq-broker",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:activemq-broker"
          ]
        }
      ],
      "title": "org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: RCE via crafted discovery URI in Jolokia JMX-HTTP bridge"
    }
  ]
}