Lucene search

K
redhatRedHatRHSA-2023:6849
HistoryNov 09, 2023 - 12:31 p.m.

(RHSA-2023:6849) Critical: Red Hat JBoss Fuse/A-MQ Fuse 6.3 R20 HF1 security and bug fix update

2023-11-0912:31:58
access.redhat.com
26
red hat
jboss fuse
a-mq
security update
bug fix
patch
cve-2023-46604
remote code execution
cvss score
activemq-openwire

8.3 High

AI Score

Confidence

Low

0.964 High

EPSS

Percentile

99.6%

Red Hat Fuse provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat A-MQ is a standards compliant messaging system that is tailored for use in mission critical applications.

This patch is an update to Red Hat Fuse 6.3 and Red Hat A-MQ 6.3. It includes bug fixes, which are documented in the patch notes accompanying the package on the download page. See the download link given in the references section below.

Security Fix(es):

  • activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack (CVE-2023-46604)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.