← Vulnerability feed

Vulnerability record · CVE-2020-13947 · published 8 February 2021

CVE-2020-13947: Apache ActiveMQ admin console message.jsp cross-site scripting

Apache · Activemq

Apache ActiveMQ versions 5.15.12 through 5.16.0 contain a reflected cross-site scripting flaw on the message.jsp page of the web-based administration console. Because the console is used to inspect and manage message queues, a successful attack can run script in the context of an authenticated administrator, which matters for environments where the console is reachable.

6.1 CVSS 3.1 Medium EPSS 79% · top 0.4% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw is a reflected XSS requiring user interaction with limited direct impact, but the affected admin console is sensitive and EPSS is very high.

What it is

Apache ActiveMQ versions 5.15.12 through 5.16.0 contain a reflected cross-site scripting flaw on the message.jsp page of the web-based administration console. Because the console is used to inspect and manage message queues, a successful attack can run script in the context of an authenticated administrator, which matters for environments where the console is reachable.

Impact

An attacker can execute arbitrary script in a victim administrator's browser session, potentially stealing session data or performing console actions as that user. The CVSS vector limits direct impact to low confidentiality and integrity with no availability effect.

Attack surface

Reached over the network via the ActiveMQ web admin console message.jsp page; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so the victim must be induced to load a crafted link or page. Scope is changed (S:C), meaning the injected script can affect resources beyond the vulnerable component.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.79 probability (99.6th percentile), but the references carry only vendor advisory and patch tags with no public exploit or PoC tag.

What to do

  • Upgrade Apache ActiveMQ past 5.16.0 to a release containing the fix, or apply the vendor advisory guidance.
  • Apply the Oracle patch referenced in the October 2021 CPU if ActiveMQ is bundled in Oracle products.
  • Restrict network access to the ActiveMQ web administration console to trusted management networks.
  • Require administrators to access the console only over trusted links and avoid clicking untrusted URLs pointing at message.jsp.
  • Deploy a content security policy or output-encoding controls on the console where feasible.

Detection

  • Review web server and ActiveMQ console logs for requests to message.jsp containing script-like or encoded payloads in parameters.
  • Monitor for anomalous administrator session activity or unexpected console actions following message.jsp access.
  • Alert on external or untrusted source IPs reaching the ActiveMQ admin console port.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13947 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed9.8CVE-2016-3088Apache ActiveMQ Fileserver unrestricted file upload to RCEThe Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 accepts HTTP PUT uploads and HTTP MOVE requests without adequate validation, lett…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.9CVE-2021-21345XStream deserialization allows remote command executionXStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, allowing code injection and OS command execution. The flaw is a …EPSS 72%analysed9.8CVE-2021-44790Apache HTTP Server mod_lua multipart parser buffer overflowA crafted request body triggers an out-of-bounds write in the mod_lua multipart parser when r:parsebody() is called from Lua scripts. The flaw affect…EPSS 97%analysed9.8CVE-2021-21347Netapp oncommand insight unrestricted file upload vulnerabilityXStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2020-13947), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.