Lucene search

K
nessusThis script is Copyright (C) 2023-2024 and is owned by Tenable, Inc. or an Affiliate thereof.ACTIVEMQ_CVE-2023-46604.NBIN
HistoryDec 07, 2023 - 12:00 a.m.

Apache ActiveMQ RCE (CVE-2023-46604)

2023-12-0700:00:00
This script is Copyright (C) 2023-2024 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
8
apache activemq
remote code execution
cve-2023-46604
binary data
scanner

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

10 High

AI Score

Confidence

High

0.964 High

EPSS

Percentile

99.6%

The remote host contains an Apache ActiveMQ version that is prior to 5.15.16, 5.16.7, 5.17.6, or 5.18.3. It is, therefore, affected by a remote code execution vulnerability. A remote attacker can exploit this and load the malicious XML of their choice from any URL and perform remote code execution.

Binary data activemq_CVE-2023-46604.nbin
VendorProductVersionCPE
apacheactivemqcpe:/a:apache:activemq

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

10 High

AI Score

Confidence

High

0.964 High

EPSS

Percentile

99.6%