Answer in brief
CVE-2023-46604 records a High severity vulnerability in Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack. The current sources mark it as known exploited. The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2023-46604 records a High severity vulnerability in Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack. The current sources mark it as known exploited. The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/Apache ActiveMQgeneric | >=5.18.0 <5.18.3 || >=5.17.0 <5.17.6 || >=5.16.0 <5.16.7 || >=0 <5.15.16 | 5.18.3, 5.17.6, 5.16.7, 5.15.16 |
| Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Modulegeneric | >=5.18.0 <5.18.3 || >=5.17.0 <5.17.6 || >=5.16.0 <5.16.7 || >=5.8.0 <5.15.16 | 5.18.3, 5.17.6, 5.16.7, 5.15.16 |
Published upstream
Oct 27, 2023
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Nov 3, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Nov 2, 2023
Evidence: source:kev:kev:kev:recordThe Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/Apache ActiveMQgeneric | >=5.18.0 <5.18.3 || >=5.17.0 <5.17.6 || >=5.16.0 <5.16.7 || >=0 <5.15.16 | 5.18.3, 5.17.6, 5.16.7, 5.15.16 |
| Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Modulegeneric | >=5.18.0 <5.18.3 || >=5.17.0 <5.17.6 || >=5.16.0 <5.16.7 || >=5.8.0 <5.15.16 | 5.18.3, 5.17.6, 5.16.7, 5.15.16 |
Published upstream
Oct 27, 2023
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Nov 3, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Nov 2, 2023
Evidence: source:kev:kev:kev:recordThe Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
Quoted source text, attributed separately from HOL analysis.