Vulnerability record · CVE-2020-13947 · published 8 February 2021
CVE-2020-13947: Apache ActiveMQ admin console message.jsp cross-site scripting
Apache · Activemq
Apache ActiveMQ versions 5.15.12 through 5.16.0 contain a reflected cross-site scripting flaw on the message.jsp page of the web-based administration console. Because the console is used to inspect and manage message queues, a successful attack can run script in the context of an authenticated administrator, which matters for environments where the console is reachable.
Description
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw is a reflected XSS requiring user interaction with limited direct impact, but the affected admin console is sensitive and EPSS is very high.
What it is
Apache ActiveMQ versions 5.15.12 through 5.16.0 contain a reflected cross-site scripting flaw on the message.jsp page of the web-based administration console. Because the console is used to inspect and manage message queues, a successful attack can run script in the context of an authenticated administrator, which matters for environments where the console is reachable.
Impact
An attacker can execute arbitrary script in a victim administrator's browser session, potentially stealing session data or performing console actions as that user. The CVSS vector limits direct impact to low confidentiality and integrity with no availability effect.
Attack surface
Reached over the network via the ActiveMQ web admin console message.jsp page; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so the victim must be induced to load a crafted link or page. Scope is changed (S:C), meaning the injected script can affect resources beyond the vulnerable component.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.79 probability (99.6th percentile), but the references carry only vendor advisory and patch tags with no public exploit or PoC tag.
What to do
- Upgrade Apache ActiveMQ past 5.16.0 to a release containing the fix, or apply the vendor advisory guidance.
- Apply the Oracle patch referenced in the October 2021 CPU if ActiveMQ is bundled in Oracle products.
- Restrict network access to the ActiveMQ web administration console to trusted management networks.
- Require administrators to access the console only over trusted links and avoid clicking untrusted URLs pointing at message.jsp.
- Deploy a content security policy or output-encoding controls on the console where feasible.
Detection
- Review web server and ActiveMQ console logs for requests to message.jsp containing script-like or encoded payloads in parameters.
- Monitor for anomalous administrator session activity or unexpected console actions following message.jsp access.
- Alert on external or untrusted source IPs reaching the ActiveMQ admin console port.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-13947 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13947), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.