CVE-2015-6524

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.

Published: 2015-08-24 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-6524 is rated Moderate Risk (52.8/100): CVSS Medium severity, with high exploitation likelihood (EPSS 8.47%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2015-6524

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-16 8.69% 8.47% -0.22%
2 2026-06-15 1.17% 8.69% +7.52%
3 2025-11-23 1.17%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-6524

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2015-6524

GitHub Security Advisory for CVE-2015-6524

GHSA-23cr-5hr4-rgwv · Severity: medium · Ecosystem: maven — Improper Input Validation in Apache ActiveMQ

OS Trackers for CVE-2015-6524

vendor priority summary link
debian low CVE-2015-6524 low priority: Debian including 1 source packages (activemq), 4 status rows across 4 suites (bookworm, bullseye, sid, trixie): resolved 4. https://security-tracker.debian.org/tracker/CVE-2015-6524
redhat medium https://access.redhat.com/security/cve/CVE-2015-6524
ubuntu medium CVE-2015-6524 medium priority: Ubuntu including 1 source packages (activemq), 8 status rows across 8 suites (precise, trusty, upstream, vivid, wily, xenial, yakkety, zesty): not-affected 4, ignored 2, released 2. https://ubuntu.com/security/CVE-2015-6524

Affected software / configurations for CVE-2015-6524

Vendor Product Version Raw CPE
fedoraproject fedora 22 cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
fedoraproject fedora 23 cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
apache activemq 5.0.0 cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:*
apache activemq 5.1.0 cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:*
apache activemq 5.2.0 cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:*
apache activemq 5.3.0 cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:*
apache activemq 5.3.1 cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:*
apache activemq 5.3.2 cpe:2.3:a:apache:activemq:5.3.2:*:*:*:*:*:*:*
apache activemq 5.4.0 cpe:2.3:a:apache:activemq:5.4.0:*:*:*:*:*:*:*
apache activemq 5.4.1 cpe:2.3:a:apache:activemq:5.4.1:*:*:*:*:*:*:*
apache activemq 5.4.2 cpe:2.3:a:apache:activemq:5.4.2:*:*:*:*:*:*:*
apache activemq 5.4.3 cpe:2.3:a:apache:activemq:5.4.3:*:*:*:*:*:*:*
apache activemq 5.5.0 cpe:2.3:a:apache:activemq:5.5.0:*:*:*:*:*:*:*
apache activemq 5.5.1 cpe:2.3:a:apache:activemq:5.5.1:*:*:*:*:*:*:*
apache activemq 5.6.0 cpe:2.3:a:apache:activemq:5.6.0:*:*:*:*:*:*:*
apache activemq 5.7.0 cpe:2.3:a:apache:activemq:5.7.0:*:*:*:*:*:*:*
apache activemq 5.8.0 cpe:2.3:a:apache:activemq:5.8.0:*:*:*:*:*:*:*
apache activemq 5.9.0 cpe:2.3:a:apache:activemq:5.9.0:*:*:*:*:*:*:*
apache activemq 5.9.1 cpe:2.3:a:apache:activemq:5.9.1:*:*:*:*:*:*:*
apache activemq 5.10.0 cpe:2.3:a:apache:activemq:5.10.0:*:*:*:*:*:*:*

References for CVE-2015-6524

cvelogic Threat Intelligence