← All CVEs

CVE-2023-46604

critical · 10Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2023-11-02Remediation due 2023-11-23

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

10
CVSS
99.7%
EPSS (exploit prob.)
100th
EPSS percentile
2023-10-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
apacheactivemq< 5.15.16
apacheactivemq>= 5.16.0, < 5.16.7
apacheactivemq>= 5.17.0, < 5.17.6
apacheactivemq>= 5.18.0, < 5.18.3
apacheactivemq_legacy_openwire_module< 5.15.16
apacheactivemq_legacy_openwire_module>= 5.16.0, < 5.16.7
apacheactivemq_legacy_openwire_module>= 5.17.0, < 5.17.6
apacheactivemq_legacy_openwire_module>= 5.18.0, < 5.18.3
debiandebian_linux10.0
debiandebian_linux11.0
netappe-series_santricity_unified_managerall versions
netappe-series_santricity_web_services_proxyall versions
netappsantricity_storage_pluginall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-46604