216.73.217.22

CVE-2023-46604

· Published 02/11/2023 01:00 · Modified 21/12/2025 01:56 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2023-46604

Essential information

Published
02/11/2023 01:00
Modified
21/12/2025 01:56
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:L/I:H/A:H

CVSS metrics

Description

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

NVD status

NVD
View on NVD