Deserialization of Untrusted Data in ActiveMQ - CVE-2023-46604

 

Deserialization of Untrusted Data in ActiveMQ - CVE-2023-46604

Published: November 2, 2023 / Updated: June 20, 2025


Vulnerability identifier: #VU82690
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46604
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data in the OpenWire protocol. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

ActiveMQ
IBM Sterling Transformation Extender
Jazz for Service Management
JBoss A-MQ
IBM Tivoli Netcool Impact
Oracle Communications Diameter Signaling Router
Bamboo Server
Oracle Communications Session Report Manager
Oracle Enterprise Data Quality
Oracle Banking APIs
IBM Operations Analytics Predictive Insights
IBM Sterling Secure Proxy
IBM Sterling Control Center
IBM Cloud Application Performance Management (APM)
Debian Linux
Ubuntu
openEuler
Wildfly
Juniper Secure Analytics (JSA)
IBM Security SOAR
IBM Qradar SIEM
IBM Cognos Command Center
IBM App Connect Professional
AMQ Broker
Fuse
Oracle Financial Services Analytical Applications Infrastructure
IBM Engineering Requirements Management DOORS Next
Oracle FLEXCUBE Private Banking
Oracle Banking Digital Experience
PowerFlex Appliance
DataPower Operations Dashboard
PowerFlex rack
Dell Security Management Server
Oracle Communications Element Manager
Web Help Desk
libactivemq-java (Ubuntu package)
activemq (Ubuntu package)
activemq-javadoc
activemq
activemq (Debian package)
HP Intelligent Management Center
Opcenter Intelligence

How to mitigate CVE-2023-46604

Install updates from vendor's website.

ActiveMQ - addressed in versions 5.15.16, 5.16.7, 5.17.6, 5.18.3
JBoss A-MQ - update to 6.3.20.1
Wildfly - update to 31.0.0
IBM Tivoli Netcool Impact - update to 7.1.0.32
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF03
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF03
AMQ Broker - addressed in versions 7.10.5, 7.11.4
Fuse - update to 7.12.1
Bamboo Server - addressed in versions 9.2.7, 9.3.5, 9.4.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM Cognos Command Center - update to 10.2.5 IF1
Web Help Desk - update to 12.8.1.824
libactivemq-java (Ubuntu package) - addressed in versions Ubuntu Pro, 5.16.1-1ubuntu0.1
activemq (Ubuntu package) - addressed in versions Ubuntu Pro, 5.16.1-1ubuntu0.1
PowerFlex Appliance - update to IC-45.373.01
DataPower Operations Dashboard - update to 1.0.20.0
IBM Operations Analytics Predictive Insights - update to 1.3.6.7
PowerFlex rack - update to 3.7.3.1
activemq-javadoc - update to 5.15.16-1
activemq - update to 5.15.16-1
activemq (Debian package) - update to 5.17.2+dfsg-2+deb12u1
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.0.0.6
HP Intelligent Management Center - update to 7.3 E0710H02
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Dell Security Management Server - update to 11.9.0
Opcenter Intelligence - update to 2501

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins