Vulnerability threat dossier

CVE-2023-46604

apacheactivemq

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

VTP deterministic threat62.0of 100 · CVSS excluded

VTP analyst assessment

Apache ActiveMQ OpenWire deserialization RCE

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Critical untrusted-data deserialization in ActiveMQ's Java OpenWire protocol can let a network attacker execute arbitrary shell commands by manipulating serialized class types. Public known exploitation and known ransomware-campaign use are recorded; no VTP observation is established.

Why it matters

  • Both Java-based OpenWire brokers and clients may be attack targets where network access is possible.
  • The 0.99723 EPSS score is predictive and does not independently prove exploitation.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The bundle does not describe current campaigns, exploit tooling, or exposed-instance prevalence.

First-party activity is unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Unexpected serialized class types or anomalous OpenWire connections.

AI baseline history (2)
  1. BASELINE ASSESSED
    Apache ActiveMQ OpenWire deserialization RCEgpt-5.6-sol · high
  2. BASELINE ASSESSED
    Apache ActiveMQ OpenWire remote code executiongpt-5.6-sol · high
Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2023-46604ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0002 Nov
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  2. 00:0002 Nov
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

ENISA EU KEV catalog membership for CVE-2023-46604

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2023-46604
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score62.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.98 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
CWE
CWE-502
CPE records
7
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.