← Vulnerability feed

Vulnerability record · CVE-2021-3425 · published 1 June 2021

CVE-2021-3425: Redhat jboss a-mq sensitive information in log file vulnerability

Redhat · Jboss A Mq

A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable.

4.4 CVSS 3.1 Medium EPSS 0.29% · top 80.6% CWE-532 · Sensitive information in log file
4.4CVSS 3.1 base score, v2 2.1
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.redhat.com/show_bug.cgi?id=1936629 Issue TrackingVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1936629 Issue TrackingVendor Advisory

Track CVE-2021-3425 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2015-7501Red Hat JBoss Java deserialization allows remote command executionMultiple Red Hat JBoss products deserialize untrusted Java objects and, through the Apache Commons Collections library, allow remote attackers to exe…EPSS 86%analysed7.5CVE-2022-1278Redhat wildfly insecure default initialization vulnerabilityA flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.EPSS 0.86%7.5CVE-2021-4104Apache Log4j 1.2 JMSAppender deserialization leads to remote code executionJMSAppender in Apache Log4j 1.2 deserializes untrusted data when an attacker can write to the Log4j configuration, allowing TopicBindingName and Topi…EPSS 81%analysed7.5CVE-2015-5183Redhat amq vulnerabilityConsole: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.EPSS 2.2%7.2CVE-2016-8648Redhat jboss a-mq deserialization of untrusted data vulnerabilityIt was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera…EPSS 2.0%6.5CVE-2023-1664Redhat build of quarkus improper certificate validation vulnerabilityA flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is…EPSS 0.43%5.6CVE-2020-14379Redhat jboss a-mq xml external entity (xxe) vulnerabilityA flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and info…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2021-3425), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.