VDB

RHSA-2023%3A6879

RHSA-2023%3A6879 PUBLISHED CVSS 9.800000190734863 CRITICAL

A flaw was found in Apache ActiveMQ, specifically the OpenWire Module. This flaw may allow a remote malicious user to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol, causing the broker to instantiate any class on the classpath. This issue happens when OpenWire commands are unmarshalled, without validating the provided throwable class type, which could allow an attacker to jeopardize the entire server.

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatAMQ Broker 7.11.4

Timeline

  • Nov 9, 2023 CVE Published
  • Mar 18, 2026 CVE Updated
  • May 2, 2026 Distribution Patch
  • May 2, 2026 Distribution Patch
  • May 2, 2026 Security Advisory
  • May 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›