VDB
RHSA-2023%3A6879
RHSA-2023%3A6879
PUBLISHED
CVSS 9.800000190734863 CRITICAL
A flaw was found in Apache ActiveMQ, specifically the OpenWire Module. This flaw may allow a remote malicious user to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol, causing the broker to instantiate any class on the classpath. This issue happens when OpenWire commands are unmarshalled, without validating the provided throwable class type, which could allow an attacker to jeopardize the entire server.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | AMQ Broker 7.11.4 |
Timeline
- Nov 9, 2023 CVE Published
- Mar 18, 2026 CVE Updated
- May 2, 2026 Distribution Patch
- May 2, 2026 Distribution Patch
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:6879 advisory
- https://access.redhat.com/security/updates/classification/#critical advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.11.4 advisory
- https://access.redhat.com/documentation/en-us/red_hat_amq_broker/7.11 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2246645 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6879.json advisory
- https://access.redhat.com/security/cve/CVE-2023-46604 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-46604 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-46604 advisory
- https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt advisory
- https://lists.apache.org/thread/y1ztwb3gktny47mj9sdv2sbw49nkgsgp advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit