Security scans or vulnerability assessments identify vulnerable versions of Apache ActiveMQ libraries (e.g., activemq-all-5.16.7.jar, activemq-broker-5.16.7.jar, or activemq-6.1.6) within the AAI installation directory.
AAI 24.4 and earlier versions bundle versions of Apache ActiveMQ that are susceptible to CVE-2026-34197. This vulnerability allows an authenticated attacker to execute arbitrary code on the broker's JVM via improper input validation in the Jolokia JMX-HTTP bridge.
This issue has been officially remediated by upgrading the bundled Apache ActiveMQ component to version 6.2.5.
Engineering addressed this remediation under defect DE187689. The following components were updated to include ActiveMQ 6.2.5 libraries:
aai.waralert-service.warsubscription-service.waractivemq.war