Deserialization of Untrusted Data in ActiveMQ - CVE-2023-46604
Published: November 2, 2023 / Updated: June 20, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in the OpenWire protocol. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Sterling Transformation Extender
Jazz for Service Management
JBoss A-MQ
IBM Tivoli Netcool Impact
Oracle Communications Diameter Signaling Router
Bamboo Server
Oracle Communications Session Report Manager
Oracle Enterprise Data Quality
Oracle Banking APIs
IBM Operations Analytics Predictive Insights
IBM Sterling Secure Proxy
IBM Sterling Control Center
IBM Cloud Application Performance Management (APM)
Debian Linux
Ubuntu
openEuler
Wildfly
Juniper Secure Analytics (JSA)
IBM Security SOAR
IBM Qradar SIEM
IBM Cognos Command Center
IBM App Connect Professional
AMQ Broker
Fuse
Oracle Financial Services Analytical Applications Infrastructure
IBM Engineering Requirements Management DOORS Next
Oracle FLEXCUBE Private Banking
Oracle Banking Digital Experience
PowerFlex Appliance
DataPower Operations Dashboard
PowerFlex rack
Dell Security Management Server
Oracle Communications Element Manager
Web Help Desk
libactivemq-java (Ubuntu package)
activemq (Ubuntu package)
activemq-javadoc
activemq
activemq (Debian package)
HP Intelligent Management Center
Opcenter Intelligence
How to mitigate CVE-2023-46604
JBoss A-MQ - update to 6.3.20.1
Wildfly - update to 31.0.0
IBM Tivoli Netcool Impact - update to 7.1.0.32
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF03
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF03
AMQ Broker - addressed in versions 7.10.5, 7.11.4
Fuse - update to 7.12.1
Bamboo Server - addressed in versions 9.2.7, 9.3.5, 9.4.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM Cognos Command Center - update to 10.2.5 IF1
Web Help Desk - update to 12.8.1.824
libactivemq-java (Ubuntu package) - addressed in versions Ubuntu Pro, 5.16.1-1ubuntu0.1
activemq (Ubuntu package) - addressed in versions Ubuntu Pro, 5.16.1-1ubuntu0.1
PowerFlex Appliance - update to IC-45.373.01
DataPower Operations Dashboard - update to 1.0.20.0
IBM Operations Analytics Predictive Insights - update to 1.3.6.7
PowerFlex rack - update to 3.7.3.1
activemq-javadoc - update to 5.15.16-1
activemq - update to 5.15.16-1
activemq (Debian package) - update to 5.17.2+dfsg-2+deb12u1
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.0.0.6
HP Intelligent Management Center - update to 7.3 E0710H02
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Dell Security Management Server - update to 11.9.0
Opcenter Intelligence - update to 2501
Links to Public Exploits and PoC-codes
- Exploit #11679 - CVE-2023-46604-RCE () (June 20, 2025)
- Exploit #11218 - CVE-2023-46604-Apache-ActiveMQ-RCE-exp (CVE-2023-46604 Apache ActiveMQ RCE exp 基于python) (March 18, 2025)
- Exploit #11085 - activemq-cve-2023-46604 (Repository to exploit CVE-2023-46604 reported for ActiveMQ) (January 23, 2025)
- Exploit #10984 - activemq-cve-2023-46604-duplicate (Repository to exploit CVE-2023-46604 reported for ActiveMQ) (December 13, 2024)
- Exploit #10795 - activemq-cve-2023-46604 (Repository to exploit CVE-2023-46604 reported for ActiveMQ) (November 4, 2024)
- Exploit #10220 - CVE-2023-46604-ActiveMQ-RCE-pseudoshell (This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserialization within the OpenWire protocol.) (July 19, 2024)
- Exploit #9846 - ActiveMQ-RCE-Exploit (ActiveMQ RCE (CVE-2023-46604) 回显利用工具) (May 23, 2024)
- Exploit #9802 - CVE-2023-46604 () (May 13, 2024)
- Exploit #9726 - cve-2023-46604 (A go-exploit for Apache ActiveMQ CVE-2023-46604) (April 19, 2024)
- Exploit #9433 - CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ ( Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604) ) (December 18, 2023)
- Exploit #9431 - CVE-2023-46604 ( CVE-2023-46604 ActiveMQ RCE vulnerability verification/exploitation tool) (December 18, 2023)
- Exploit #9403 - Apache ActiveMQ Unauthenticated Remote Code Execution (November 6, 2023)
- Exploit #9400 - ActiveMQ-RCE (ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具) (November 2, 2023)
External References
Related Security Bulletins
- Remote code execution in Apache ActiveMQ
- Atlassian Bamboo Data Center and Server update for Apache ActiveMQ
- Multiple vulnerabilities in Red Hat Fuse 7.12
- Remote code execution in Red Hat AMQ Broker 7.11
- Remote code execution in Red Hat AMQ Broker 7.10
- Remote code execution in Red Hat JBoss Fuse/A-MQ Fuse
- Multiple vulnerabilities in IBM QRadar SIEM
- IBM Tivoli Netcool Impact update for Apache ActiveMQ
- IBM Operations Analytics Predictive Insights update for Apache ActiveMQ
- Deserialization of untrusted data in IBM Security SOAR
- Dell Security Management Server update for Apache ActiveMQ
- Multiple vulnerabilities in HPE Intelligent Management Center
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- IBM App Connect Professional update for Apache ActiveMQ
- Deserialization of Untrusted Data in Oracle Enterprise Data Quality
- Deserialization of Untrusted Data in Oracle Communications Session Report Manager
- Deserialization of Untrusted Data in Oracle Communications Element Manager
- Deserialization of untrusted data in IBM Jazz for Service Management
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure
- Multiple vulnerabilities in Oracle Banking Digital Experience
- Multiple vulnerabilities in Oracle Banking APIs
- WildFly update for third-party components
- Multiple vulnerabilities in IBM Sterling Transformation Extender
- Multiple vulnerabilities in IBM Application Performance Management
- Deserialization of untrusted data in IBM DataPower Operations Dashboard
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler update for activemq
- Multiple vulnerabilities in IBM Secure Proxy
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in Oracle FLEXCUBE Private Banking
- SolarWinds Web Help Desk update for Apache ActiveMQ
- Ubuntu update for activemq
- Deserialization of Untrusted Data in IBM Sterling Control Center
- Debian update for activemq
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Dell PowerFlex appliance
- Multiple vulnerabilities in Dell PowerFlex rack
- Multiple vulnerabilities in Siemens Opcenter Intelligence
- Ubuntu update for activemq