Apache ActiveMQ CVE-2023-46604 Remote Code Execution Vulnerability
Description
Apache ActiveMQ Java OpenWire broker or client is vulnerable to remote code execution via manipulation of serialized class types in the OpenWire protocol, allowing attackers to instantiate arbitrary classes on the classpath.
Outbreak Alert
Ransomware attackers are targeting servers running outdated and vulnerable versions of Apache ActiveMQ by exploiting a recently fixed vulnerability (CVE-2023-46604).
Affected Applications
Apache ActiveMQ
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2023-11-02 | 1.00569 |
New
|
Apache ActiveMQ |