Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
Each line is one product that two or more sources describe differently. Same identifier means they both named it the same way; linked identifier means they named it differently and meet at a package URL or CPE both assert. This is recorded rather than resolved: a vendor saying "not affected" where an ecosystem says "affected" is a fact about the disclosure, and flattening it would hide the more useful half.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_fuse_7:activemq-all activemq-all as a component of Red Hat Fuse 7 | not affected vulnerable code not present | no version stated vendor label: activemq-all | not applicable | csaf_redhat | |
| red_hat_amq_broker_7:activemq-broker activemq-broker as a component of Red Hat AMQ Broker 7 | not affected vulnerable code not in execute path | no version stated vendor label: activemq-broker | not applicable | csaf_redhat | |
| red_hat_data_grid_8:activemq-broker activemq-broker as a component of Red Hat Data Grid 8 | not affected component not present | no version stated vendor label: activemq-broker | not applicable | csaf_redhat | |
| red_hat_fuse_7:activemq-broker activemq-broker as a component of Red Hat Fuse 7 | not affected vulnerable code not present | no version stated vendor label: activemq-broker | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_7:activemq-broker activemq-broker as a component of Red Hat JBoss Enterprise Application Platform 7 | not affected vulnerable code not present | no version stated vendor label: activemq-broker | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_8:activemq-broker activemq-broker as a component of Red Hat JBoss Enterprise Application Platform 8 | not affected vulnerable code not present | no version stated vendor label: activemq-broker | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_expansion_pack:activemq-broker activemq-broker as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack | not affected vulnerable code not present | no version stated vendor label: activemq-broker | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:log4j log4j as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: log4j | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:log4j-jcl log4j-jcl as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: log4j-jcl | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:log4j-jcl log4j-jcl as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: log4j-jcl | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:log4j-slf4j log4j-slf4j as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: log4j-slf4j | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:log4j-slf4j log4j-slf4j as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: log4j-slf4j | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:log4j-web log4j-web as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: log4j-web | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:log4j.src log4j.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: log4j.src | not applicable | csaf_redhat | |
| activemq | affected | < 5.19.4 | vendor fix → 5.19.4 | osv BIT-activemq-2026-34197 | |
| activemq | affected | >= 6.0.0, < 6.2.3 | vendor fix → 6.2.3 | osv BIT-activemq-2026-34197 | |
| https://github.com/apache/activemq | affected | < 2c1b9eefa68c684083478bfa4a9bcf42892f33ec | vendor fix → 2c1b9eefa68c684083478bfa4a9bcf42892f33ec | osv | |
| https://github.com/apache/activemq | affected | >= 14bac13f40958c1a1d3d198051eed32facc4abd1, < d8ce71364638fe4a18ae7531bd1f69f7543e2f16 | vendor fix → d8ce71364638fe4a18ae7531bd1f69f7543e2f16 | osv | |
| org.apache.activemq:activemq-all | affected | < 5.19.5 | vendor fix → 5.19.5 | osv GHSA-rxpj-7qvf-xv32 | |
| org.apache.activemq:activemq-all | affected | >= 6.0.0, < 6.2.3 | vendor fix → 6.2.3 | osv GHSA-rxpj-7qvf-xv32 | |
| org.apache.activemq:activemq-broker | affected | < 5.19.5 | vendor fix → 5.19.5 | osv GHSA-rxpj-7qvf-xv32 | |
| org.apache.activemq:activemq-broker | affected | >= 6.0.0, < 6.2.3 | vendor fix → 6.2.3 | osv GHSA-rxpj-7qvf-xv32 | |
| activemq | fixed | 5.19.4 | vendor fix → 5.19.4 | osv BIT-activemq-2026-34197 | |
| activemq | fixed | 6.2.3 | vendor fix → 6.2.3 | osv BIT-activemq-2026-34197 | |
| https://github.com/apache/activemq | fixed | 2c1b9eefa68c684083478bfa4a9bcf42892f33ec | vendor fix → 2c1b9eefa68c684083478bfa4a9bcf42892f33ec | osv | |
| https://github.com/apache/activemq | fixed | d8ce71364638fe4a18ae7531bd1f69f7543e2f16 | vendor fix → d8ce71364638fe4a18ae7531bd1f69f7543e2f16 | osv | |
| org.apache.activemq:activemq-all | fixed | 5.19.5 | vendor fix → 5.19.5 | osv GHSA-rxpj-7qvf-xv32 | |
| org.apache.activemq:activemq-all | fixed | 6.2.3 | vendor fix → 6.2.3 | osv GHSA-rxpj-7qvf-xv32 | |
| org.apache.activemq:activemq-broker | fixed | 5.19.5 | vendor fix → 5.19.5 | osv GHSA-rxpj-7qvf-xv32 | |
| org.apache.activemq:activemq-broker | fixed | 6.2.3 | vendor fix → 6.2.3 | osv GHSA-rxpj-7qvf-xv32 | |
| Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:apache-activemq Apache Software Foundation · Apache ActiveMQ | affected | < 5.19.4 | none available | cve_cna | |
| Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:apache-activemq Apache Software Foundation · Apache ActiveMQ | affected | >= 6.0.0, < 6.2.3 | none available | cve_cna | |
| Apache Software Foundation/Apache ActiveMQ All/org.apache.activemq:activemq-all Apache Software Foundation · Apache ActiveMQ All | affected | < 5.19.4 | none available | cve_cna | |
| Apache Software Foundation/Apache ActiveMQ All/org.apache.activemq:activemq-all Apache Software Foundation · Apache ActiveMQ All | affected | >= 6.0.0, < 6.2.3 | none available | cve_cna | |
| Apache Software Foundation/Apache ActiveMQ Broker/org.apache.activemq:activemq-broker Apache Software Foundation · Apache ActiveMQ Broker | affected | < 5.19.4 | none available | cve_cna | |
| Apache Software Foundation/Apache ActiveMQ Broker/org.apache.activemq:activemq-broker Apache Software Foundation · Apache ActiveMQ Broker | affected | >= 6.0.0, < 6.2.3 | none available | cve_cna | |
| Red Hat/Red Hat JBoss Enterprise Application Platform Expansion Pack/activemq-broker Red Hat · Red Hat JBoss Enterprise Application Platform Expansion Pack | affected | no version stated vendor label: all versions | none available | cve_adp | |
| Red Hat/Red Hat AMQ Broker 7/activemq-broker Red Hat · Red Hat AMQ Broker 7 | not affected | no version stated vendor label: all versions | not applicable | cve_adp | |
| Red Hat/Red Hat Data Grid 8/activemq-broker Red Hat · Red Hat Data Grid 8 | not affected | no version stated vendor label: all versions | not applicable | cve_adp | |
| Red Hat/Red Hat Enterprise Linux 8/log4j:2/log4j Red Hat · Red Hat Enterprise Linux 8 | not affected | no version stated vendor label: all versions | not applicable | cve_adp | |
| Red Hat/Red Hat Enterprise Linux 9/log4j Red Hat · Red Hat Enterprise Linux 9 | not affected | no version stated vendor label: all versions | not applicable | cve_adp | |
| Red Hat/Red Hat Fuse 7/activemq-all Red Hat · Red Hat Fuse 7 | not affected | no version stated vendor label: all versions | not applicable | cve_adp | |
| Red Hat/Red Hat Fuse 7/activemq-broker Red Hat · Red Hat Fuse 7 | not affected | no version stated vendor label: all versions | not applicable | cve_adp | |
| Red Hat/Red Hat JBoss Enterprise Application Platform 7/activemq-broker Red Hat · Red Hat JBoss Enterprise Application Platform 7 | not affected | no version stated vendor label: all versions | not applicable | cve_adp | |
| Red Hat/Red Hat JBoss Enterprise Application Platform 8/activemq-broker Red Hat · Red Hat JBoss Enterprise Application Platform 8 | not affected | no version stated vendor label: all versions | not applicable | cve_adp |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.