← voltar
CVE-2023-46604criticalsob ataqueransomwareCWE-502

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

100Vexday Risk Score

Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.

ssvc Actcvss 10epss 100%
da publicação à arma0 dias
Publicada no NVD27 de out.
1ª PoC26 de out.
metasploit27 de out.
CISA KEV+6d
probabilidade de exploração
100%top 1% das CVEs
exploração observada
simCISA + VulnCheck
66 exploit(s) público(s)
O que os fabricantes declaram (VEX)

Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.

Afetado
1 produto
Red Hat JBoss Fuse Service Works 6
workaround: In affected systems, it may be possible to mitigate some of the risks from this vulnerability. However this mitigation cannot eliminate all risks; the only complete resolution is to apply software updates…
Corrigido
6 produtos
AMQ 6.3 openshift container image · AMQ Broker 7.10.5 · AMQ Broker 7.11.4 · Middleware RHEL 7 Containers for OpenShift · Red Hat Fuse 7.12.1 · e outros 1
Ação exigida pela CISAprazo federal: 2023-11-23

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
PoCs públicas encontradas — 66
githubgithub.com/SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ★ 126githubgithub.com/Catherines77/ActiveMQ-EXPtools★ 77githubgithub.com/Arlenhiack/ActiveMQ-RCE-Exploit★ 43githubgithub.com/evkl1d/CVE-2023-46604★ 40githubgithub.com/trganda/ActiveMQ-RCE★ 28githubgithub.com/duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell★ 18githubgithub.com/justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp★ 5githubgithub.com/vulncheck-oss/cve-2023-46604★ 4githubgithub.com/h3x3h0g/ActiveMQ-RCE-CVE-2023-46604-Write-up★ 3githubgithub.com/NKeshawarz/CVE-2023-46604-RCE★ 3githubgithub.com/LiritoShawshark/CVE-2023-46604_ActiveMQ_RCE_Recurrence★ 2githubgithub.com/dcm2406/CVE-Lab★ 2githubgithub.com/RockyDesigne/SSP-Assignment-3-RCEYouLater★ 2githubgithub.com/mrpentst/CVE-2023-46604★ 2githubgithub.com/vaishnavucv/Project-Vuln-Detection-N-Mitigation_101★ 1githubgithub.com/pulentoski/CVE-2023-46604★ 1githubgithub.com/skrkcb2/CVE-2023-46604★ 1githubgithub.com/stegano5/ExploitScript-CVE-2023-46604★ 1githubgithub.com/minhangxiaohui/ActiveMQ_CVE-2023-46604★ 1githubgithub.com/dcm2406/CVE-2023-46604★ 0githubgithub.com/vjayant93/CVE-2023-46604-POC★ 0githubgithub.com/CrackerCat/ActiveMQ_RCE_Pro_Max★ 0githubgithub.com/nitzanoligo/CVE-2023-46604-demo★ 0githubgithub.com/Mudoleto/Broker_ApacheMQ★ 0githubgithub.com/tomasmussi/activemq-cve-2023-46604★ 0githubgithub.com/thinkycx/activemq-rce-cve-2023-46604★ 0githubgithub.com/mranv/honeypot.rs★ 0githubgithub.com/cuanh2333/CVE-2023-46604★ 0githubgithub.com/CCIEVoice2009/CVE-2023-46604★ 0githubgithub.com/pavanaa4k/CVE-2023-46604-LAB★ 0githubgithub.com/sangrok-jeon/CVE-2023-46604-Analysis★ 0githubgithub.com/mkdemir/activemq-lockbit-analysis★ 0githubgithub.com/Navya240/intel471-threat-hunting-cve-2023-46604★ 0githubgithub.com/KlaasStessens/CVE-2023-46604★ 0githubgithub.com/trnguyen03/activemq-ids-ips-lab★ 0githubgithub.com/REGGYRAIDER/CVE-2023-46604-RCE★ 0githubgithub.com/aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation★ 0vulncheckvulncheck.com/xdb/ac860bc0b755não verificadovulncheckvulncheck.com/xdb/8ccea255e61cnão verificadovulncheckvulncheck.com/xdb/1e134f0874f8não verificadovulncheckvulncheck.com/xdb/5f38a93c3fe0não verificadovulncheckvulncheck.com/xdb/c01880ea274bnão verificadovulncheckvulncheck.com/xdb/2a263bac5fa9não verificadovulncheckvulncheck.com/xdb/90299d8578e8não verificadovulncheckvulncheck.com/xdb/7adf2c60412fnão verificadovulncheckvulncheck.com/xdb/c1ad06a8233fnão verificadovulncheckvulncheck.com/xdb/d6b987f7cb4cnão verificadovulncheckvulncheck.com/xdb/adc63f08a561não verificadovulncheckvulncheck.com/xdb/111d5aa9554fnão verificadovulncheckvulncheck.com/xdb/7d454efa423fnão verificadovulncheckvulncheck.com/xdb/f688c01da056não verificadovulncheckvulncheck.com/xdb/26ec274f11a6não verificadovulncheckvulncheck.com/xdb/bd01e441da28não verificadovulncheckvulncheck.com/xdb/cc4ca3b4d289não verificadovulncheckvulncheck.com/xdb/9c19a15a7306não verificadovulncheckvulncheck.com/xdb/9af52ad961cenão verificadovulncheckvulncheck.com/xdb/bf84564c744cnão verificadovulncheckvulncheck.com/xdb/e3eff001f1dbnão verificadovulncheckvulncheck.com/xdb/453453dd752fnão verificadocve_referencepacketstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.htmlnão verificadovulncheckvulncheck.com/xdb/f5d0e2739b8cnão verificadovulncheckvulncheck.com/xdb/8ce9f74afedcnão verificadovulncheckvulncheck.com/xdb/28c5231dc0c7não verificadovulncheckvulncheck.com/xdb/0e3786dc85bbnão verificadovulncheckvulncheck.com/xdb/07dca85f6442não verificadovulncheckvulncheck.com/xdb/0462e934919bnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.