<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:06:54 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-07372</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07372</link>
      <description>bdu:2023-07372</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07372</guid>
    </item>
    <item>
      <title>BIT-activemq-2023-46604 — Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to…</title>
      <link>https://cve.radiocsirt.org/vuln/bit-activemq-2023-46604</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code 
Execution. This vulnerability may allow a remote attacker with network 
access to either a Java-based OpenWire broker or client to run arbitrary
 shell commands by manipulating serialized class types in the OpenWire 
protocol to cause either the client or the broker (respectively) to 
instantiate any class on the classpath.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade
 both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 
which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code 
Execution. This vulnerability may allow a remote attacker with network 
access to either a Java-based OpenWire broker or client to run arbitrary
 shell commands by manipulating serialized class types in the OpenWire 
protocol to cause either the client or the broker (respectively) to 
instantiate any class on the classpath.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade
 both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 
which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-activemq-2023-46604</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0919 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;les
produits SolarWinds&lt;/span&gt;. Elle permet à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0919</link>
      <description>certfr-2023-avi-0919</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0919</guid>
    </item>
    <item>
      <title>cnvd-2023-94073</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-94073</link>
      <description>cnvd-2023-94073</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-94073</guid>
    </item>
    <item>
      <title>EUVD-2026-258476</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258476</link>
      <description>EUVD-2026-258476</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258476</guid>
    </item>
    <item>
      <title>fkie_cve-2023-46604</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46604</link>
      <description>&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code 
Execution. This vulnerability may allow a remote attacker with network 
access to either a Java-based OpenWire broker or client to run arbitrary
 shell commands by manipulating serialized class types in the OpenWire 
protocol to cause either the client or the broker (respectively) to 
instantiate any class on the classpath.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade
 both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 
which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code 
Execution. This vulnerability may allow a remote attacker with network 
access to either a Java-based OpenWire broker or client to run arbitrary
 shell commands by manipulating serialized class types in the OpenWire 
protocol to cause either the client or the broker (respectively) to 
instantiate any class on the classpath.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade
 both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 
which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-46604</guid>
    </item>
    <item>
      <title>GHSA-crg9-44h2-xw35 — Apache ActiveMQ is vulnerable to Remote Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-crg9-44h2-xw35</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-client, Maven: org.apache.activemq:activemq-openwire-legacy&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-client, Maven: org.apache.activemq:activemq-openwire-legacy&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-crg9-44h2-xw35</guid>
    </item>
    <item>
      <title>gsd-2023-46604</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-46604</link>
      <description>gsd-2023-46604</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-46604</guid>
    </item>
    <item>
      <title>ICSA-24-130-03 — Delta Electronics InfraSuite Device Master</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-130-03</link>
      <description>&lt;p&gt;Delta Electronics InfraSuite Device Master contains a deserialization of untrusted data vulnerability because it runs a version of Apache ActiveMQ (5.15.2) which is vulnerable to CVE-2023-46604.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Delta Electronics InfraSuite Device Master contains a deserialization of untrusted data vulnerability because it runs a version of Apache ActiveMQ (5.15.2) which is vulnerable to CVE-2023-46604.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-130-03</guid>
    </item>
    <item>
      <title>OESA-2023-1778 — activemq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1778</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: activemq, openEuler:20.03-LTS-SP3: activemq, openEuler:22.03-LTS: activemq, openEuler:22.03-LTS-SP1: activemq, openEuler:22.03-LTS-SP2: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. &#13;
&#13;
Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.(CVE-2023-46604)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: activemq, openEuler:20.03-LTS-SP3: activemq, openEuler:22.03-LTS: activemq, openEuler:22.03-LTS-SP1: activemq, openEuler:22.03-LTS-SP2: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. &#13;
&#13;
Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.(CVE-2023-46604)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1778</guid>
    </item>
    <item>
      <title>OXAS-ADV-2024-0001 — OX App Suite Security Advisory OXAS-ADV-2024-0001</title>
      <link>https://cve.radiocsirt.org/vuln/oxas-adv-2024-0001</link>
      <description>OXAS-ADV-2024-0001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oxas-adv-2024-0001</guid>
    </item>
    <item>
      <title>RHSA-2023:6849 — Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ Fuse 6.3 R20 HF1 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:6849</link>
      <description>&lt;p&gt;activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:6849</guid>
    </item>
    <item>
      <title>SCA-2024-0001 — Vulnerability in SICK Logistics Analytics Products and SICK Field Analytics</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2024-0001</link>
      <description>&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both Apache ActiveMQ Classic and Apache ActiveMQ Legacy brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both Apache ActiveMQ Classic and Apache ActiveMQ Legacy brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2024-0001</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-46604</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46604</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:22.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary  shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade  both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:22.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary  shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade  both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46604</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2773 — Apache ActiveMQ: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2773</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache ActiveMQ ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache ActiveMQ ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2773</guid>
    </item>
  </channel>
</rss>
