CVE-2023-46604
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-502
מוצרים מושפעים
apache: activemq; apache: activemq legacy openwire module; debian: debian linux; netapp: e-series santricity unified manager; netapp: e-series santricity web services proxy; netapp: santricity storage plugin
קישורים
- https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announceme… Vendor Advisory
- https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announceme… Vendor Advisory
- https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-R… ExploitThird Party AdvisoryVDB Entry
- https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-R… ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2024/Apr/18 Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html Mailing List
- https://security.netapp.com/advisory/ntap-20231110-0010/ Third Party Advisory
- https://www.openwall.com/lists/oss-security/2023/10/27/5 Mailing List
- http://seclists.org/fulldisclosure/2024/Apr/18 Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html Mailing List