PT-2023-6605 · Apache+4 · Apache Activemq+4

·

CVE-2023-46604

·

Published

2023-10-27

·

Updated

2026-09-03

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.15.16 Apache ActiveMQ versions 5.16.x through 5.16.6 Apache ActiveMQ versions 5.17.x through 5.17.5 Apache ActiveMQ versions 5.18.x through 5.18.2 Bamboo Data Center (affected versions not specified) Bamboo Server (affected versions not specified)
Description The Java OpenWire protocol marshaller is susceptible to Remote Code Execution (RCE) due to the deserialization of untrusted data. A remote attacker with network access to a Java-based OpenWire broker or client can execute arbitrary shell commands by manipulating serialized class types to force the instantiation of any class on the classpath. Technical exploitation involves using the OpenWire protocol to load malicious configuration files via Java Spring classes, such as ClassPathXmlApplicationContext or FileSystemXmlApplicationContext, to achieve RCE without authentication. Approximately 3,000 servers worldwide have been identified as vulnerable. Real-world incidents include the deployment of LockBit ransomware, Mauricrypt, and Cobalt Strike by threat actors such as Andariel, often utilizing certutil.exe to drop stagers and SystemSettingsAdminFlows.exe to disable security software.
Recommendations Update Apache ActiveMQ to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3. Update Bamboo Data Center to version 9.2.7, 9.3.5, 9.4.1 or later. Update Bamboo Server to version 9.2.7, 9.3.5, 9.4.1 or later.

Exploit

Fix

LPE

RCE

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

APACHEACTIVEMQ_CVE2023_46604
BDU:2023-07372
BIT-ACTIVEMQ-2023-46604
CVE-2023-46604
DLA-3657-1
DLA-3936-1
DSA-5798-1
GHSA-CRG9-44H2-XW35
OESA-2023-1778
USN-6910-1
USN-7268-1
ZDI-24-440

Affected Products

Apache Activemq
Bamboo
Linuxmint
Red Os
Ubuntu