peter bassill · operator
$ cve CVE-2023-46604 JSON

CVE-2023-46604 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-11-23.

Description

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
EPSS99.89% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2023-11-23
Public exploitnone known
Published2023-10-27
Last modified2026-06-17

CISA KEV

NameApache ActiveMQ Deserialization of Untrusted Data Vulnerability
Added2023-11-02
Due2023-11-23
Vendor / productApache / ActiveMQ
Ransomware useknown

Affected (6)

VendorProduct
apacheactivemq
apacheactivemq legacy openwire module
debiandebian linux
netappe-series santricity unified manager
netappe-series santricity web services proxy
netappsantricity storage plugin

References

→ the Explorer  ·  watch your stack  ·  NVD