CVE Database
/

CVE-2023-46604

Back to search

CVE-2023-46604

Published: Oct 27, 2023

Modified: Nov 3, 2025

PUBLISHED

CVSS v3.1

10.0

CRITICAL

Description

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

VendorProductVersions

Apache Software Foundation

Apache ActiveMQ

affected
5.18.0 - < 5.18.3
affected
5.17.0 - < 5.17.6
affected
5.16.0 - < 5.16.7
affected
0 - < 5.15.16

Apache Software Foundation

Apache ActiveMQ Legacy OpenWire Module

affected
5.18.0 - < 5.18.3
affected
5.17.0 - < 5.17.6
affected
5.16.0 - < 5.16.7
affected
5.8.0 - < 5.15.16

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now