CVE-2023-46604 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-11-23.
Description
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H |
| EPSS | 99.89% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | yes — remediate by 2023-11-23 |
| Public exploit | none known |
| Published | 2023-10-27 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apache ActiveMQ Deserialization of Untrusted Data Vulnerability |
|---|---|
| Added | 2023-11-02 |
| Due | 2023-11-23 |
| Vendor / product | Apache / ActiveMQ |
| Ransomware use | known |
Affected (6)
| Vendor | Product |
|---|---|
| apache | activemq |
| apache | activemq legacy openwire module |
| debian | debian linux |
| netapp | e-series santricity unified manager |
| netapp | e-series santricity web services proxy |
| netapp | santricity storage plugin |
References
- http://seclists.org/fulldisclosure/2024/Apr/18
- https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt
- https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html
- https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html
- https://security.netapp.com/advisory/ntap-20231110-0010/
- https://www.openwall.com/lists/oss-security/2023/10/27/5
- http://seclists.org/fulldisclosure/2024/Apr/18
- https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt
- https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html
- https://lists.debian.org/debian-lts-announce/2024/10/msg00027.html
- https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html
- https://security.netapp.com/advisory/ntap-20231110-0010/
- https://www.openwall.com/lists/oss-security/2023/10/27/5
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46604
→ the Explorer · watch your stack · NVD