Exposure of Sensitive Information Through Metadata Affecting apache-tomee package, versions <10.1.5-r2


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.51% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-APACHETOMEE-17939519
  • published10 Jul 2026
  • disclosed1 Jun 2026

Introduced: 1 Jun 2026

CVE-2026-49270  (opens in a new tab)
CWE-1230  (opens in a new tab)

How to fix?

Upgrade Chainguard apache-tomee to version 10.1.5-r2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream apache-tomee package and not the apache-tomee package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.

Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.

Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS Base Scores

version 3.1