TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2023-46604

CRITICALCISA KEV
10.0

Beschreibung

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

CVE Details

CVSS v3.1 Bewertung10.0
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht10/27/2023
Zuletzt geandert11/4/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerApache
ProduktActiveMQ
SchwachstellennameApache ActiveMQ Deserialization of Untrusted Data Vulnerability
KEV Aufnahmedatum2023-11-02
Behebungsfrist2023-11-23
Ransomware-NutzungKnown

Betroffene Produkte

apache:activemqapache:activemq_legacy_openwire_moduledebian:debian_linuxnetapp:e-series_santricity_unified_managernetapp:e-series_santricity_web_services_proxynetapp:santricity_storage_plugin

Schwachen (CWE)

CWE-502

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.