Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-46604

98
FAUCET Score

CVE-2023-46604 is a critical Remote Code Execution vulnerability affecting the Java OpenWire protocol marshaller in Apache ActiveMQ, Debian, and NetApp products. It allows unauthenticated remote attackers to execute arbitrary shell commands by manipulating serialized class types. With a CVSS score of 9.8 (Critical) and an EPSS score of 0.94436, this vulnerability poses a severe risk due to its network-based attack vector and low complexity. It is actively exploited in the wild, including by LockBit, DripDropper, TellYouThePass, HelloKitty, and Kinsing ransomware campaigns, with a Metasploit module publicly available and significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.15.16CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 5.16.0, < 5.16.7CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 5.17.0, < 5.17.6CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 5.18.0, < 5.18.3CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
< 5.15.16CPE matchmatch criteria
cpe:2.3:a:apache:activemq_legacy_openwire_module:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.65%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · Nov 2, 2023
Metasploit: Apache ActiveMQ Unauthenticated Remote Code Execution · Oct 27, 2023
Nuclei: CVE-2023-46604 · Dec 12, 2023
This CVE's current EPSS score of 0.9965 is in the 100th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (23)

barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
esetpatch availablevia llm_extracted
freshrsspatch availablevia llm_extracted
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 5.17.6
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 5.18.3
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.15.16
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.16.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.17.6
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.18.3
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 5.15.16
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-openwire-legacyFixed in: 5.16.7
qdrantpatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: RHEL-7 based Middleware ContainersFixed in: jboss-amq-6/amq63-openshift:1.4-50
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse/AMQ 6.3.20Fixed in: activemq-openwire
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.12.1Fixed in: activemq-openwire
View patch
redhatpatch availablevia redhat_api
Product: AMQ 6.3 openshift container image
View patch
redhatpatch availablevia redhat_api
Product: AMQ Broker 7.11.4Fixed in: activemq-openwire
View patch
redhatpatch availablevia redhat_api
Product: AMQ Broker 7.10.5
View patch
symantecpatch availablevia llm_extracted
verbbpatch availablevia llm_extracted

Vendor Advisories (11)

esetllm-eset-9b3362eab340e025

CVE-2023-46604

Apr 1, 2024
qdrantllm-qdrant-18fe011ff2bb332d

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
boschllm-bosch-858b4649d43a4477

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
freshrssllm-freshrss-6291b73cdec9af86

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
barracudallm-barracuda-df1207e034e6a16d

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
symantecllm-symantec-0b8bb7a0e6ad87d5

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
verbbllm-verbb-192e71367281b534

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
consulllm-consul-64d80b207e035838

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
clamavllm-clamav-4fe46cd07f63621e

Remote Code Execution Vulnerability in Apache ActiveMQ

Nov 6, 2023
mavenGHSA-crg9-44h2-xw35critical

Apache ActiveMQ is vulnerable to Remote Code Execution

Oct 27, 2023
redhatCVE-2023-46604Critical

activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

Oct 27, 2023

References

cisa.gov / known-exploited-vulnerabilities-catalog
Third Party AdvisoryUS Government Resource
lists.debian.org / debian-lts-announce/2024/10/msg00027.html
Mailing List
activemq.apache.org / security-advisories.data/CVE-2023-46604-announcement.txt
Vendor Advisory
seclists.org / fulldisclosure/2024/Apr/18
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/11/msg00013.html
Mailing List
packetstormsecurity.com / files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html
ExploitThird Party AdvisoryVDB Entry
security.netapp.com / advisory/ntap-20231110-0010
Third Party Advisory
openwall.com / lists/oss-security/2023/10/27/5
Mailing List