The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
| Vendor | Product | Versions |
|---|---|---|
| apache | activemq | < 5.15.16, < 5.16.7, < 5.17.6, < 5.18.3, < 5.15.16, < 5.16.7, < 5.17.6, < 5.18.3, < 5.19.4, 6.0.0 - 6.2.3, 6.2.3 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | activemq_legacy_openwire_module | cve_cpe | 95% |
| atlassian | fisheye | cert_advisory | 90% |
| atlassian | confluence | cert_advisory | 90% |
| atlassian | bitbucket | cert_advisory | 90% |
| atlassian | crucible | cert_advisory | 90% |
Updated affected versions to include 6.2.3 and 5.19.4, changed severity to HIGH, and added new IoCs and tags.
Updated severity to HIGH, added new patch versions 6.2.3 and 5.19.4, included new CWE ID CWE-20, and added new relevant CVE tags.
Updated description with detailed exploit information, changed severity to HIGH, updated CVSS to 8.8, and added new affected versions and CVE IDs.
Initial creation