Apache ActiveMQ Remote Code Execution (CVE-2023-46604)

Related Vulnerabilities: CVE-2023-46604  

Check Point Reference: CPAI-2023-1080 Date Published: 5 Nov 2023 Severity: Critical Last Updated: Monday 18 December, 2023 Source: Industry Reference:CVE-2023-46604
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Apache ActiveMQ before 5.15.16
Apache ActiveMQ 5.16.0 before 5.16.7
Apache ActiveMQ 5.17.0 before 5.17.6
Apache ActiveMQ 5.18.0 before 5.18.3

Apache ActiveMQ Legacy OpenWire Module 5.8.0 before 5.15.16
Apache ActiveMQ Legacy OpenWire Module 5.16.0 before 5.16.7

Apache ActiveMQ Legacy OpenWire Module 5.17.0 before 5.17.6
Apache ActiveMQ Legacy OpenWire Module 5.18.0 before 5.18.3 Vulnerability Description A remote code execution vulnerability exists in Apache ActiveMQ. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.