CVE-2023-46604 - Apache ActiveMQ
AI Vulnerability ContextThe Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upg...
Overview
A source-backed snapshot of this vulnerability.
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath.
Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2023-46604
- Vendor/project
- Apache
- Product
- ActiveMQ
- Vulnerability name
- Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
- Date added
- 2023-11-02
- Due date
- 2023-11-23
- Known ransomware campaign use
- Known
- CVSS v3
- 10.0
Exploit context
What the vulnerability is about.
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath.
Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
