CVE-2023-46604: listed in the CISA KEV catalog CVE-2023-46604 · CVSS 10.0 CRITICAL · EPSS 99.9% · KEV 2023-11-02 · patch available
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to either a Java-based OpenWire broker or client to run arbitrary
shell commands by manipulating serialized class types in the OpenWire
protocol to cause either the client or the broker (respectively) to
instantiate any class on the classpath.
Users are recommended to upgrade
both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3
which fixes this issue.
Is CVE-2023-46604 exploited? Listed in the CISA KEV catalog on 2023-11-02. Federal remediation due 2023-11-23. Past that date by 1043 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 99.9%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? Atlassian · Bamboo · Data Center LTS <10.2.22 Atlassian · Bamboo · Data Center LTS <12.1.10 Atlassian · Jira · Data Center LTS <10.3.24 Atlassian · Bitbucket · Data Center <10.4.2 Dell · Secure Connect Gateway · <5.36.00.16 Atlassian · Bitbucket · Data Center LTS <9.4.23 Atlassian · Bitbucket · Data Center LTS <10.2.6 Atlassian · Confluence · Data Center LTS <9.2.23 Atlassian · Confluence · Data Center LTS <10.2.15 Atlassian · Fisheye · <4.9.13 Atlassian · Crucible · <4.9.13 Atlassian · Jira · Data Center LTS <11.3.10 Apache Software Foundation · Apache ActiveMQ · >= 5.18.0, < 5.18.3, >= 5.17.0, < 5.17.6, >= 5.16.0, < 5.16.7, >= 0, < 5.15.16 Apache Software Foundation · Apache ActiveMQ Legacy OpenWire Module · >= 5.18.0, < 5.18.3, >= 5.17.0, < 5.17.6, >= 5.16.0, < 5.16.7, >= 5.8.0, < 5.15.16 debian · debian linux · 10.0, 11.0 netapp · e-series santricity unified manager netapp · e-series santricity web services proxy netapp · santricity storage plugin Is there a patch? Bamboo Data Center LTS 10.2.22 Bamboo Data Center LTS 12.1.10 Jira Data Center LTS 10.3.24 Bitbucket Data Center 10.4.2 Secure Connect Gateway 5.36.00.16 Bitbucket Data Center LTS 9.4.23 Bitbucket Data Center LTS 10.2.6 Confluence Data Center LTS 9.2.23 Confluence Data Center LTS 10.2.15 Fisheye 4.9.13 Crucible 4.9.13 Jira Data Center LTS 11.3.10 What PlainSec published about CVE-2023-46604 Primary sources KEV and EPSS are re-checked daily. Record last updated 2026-10-01.
CVE-2023-46604: listed in the CISA KEV catalog CVE-2023-46604 · CVSS 10.0 CRITICAL · EPSS 99.9% · KEV 2023-11-02 · patch available
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to either a Java-based OpenWire broker or client to run arbitrary
shell commands by manipulating serialized class types in the OpenWire
protocol to cause either the client or the broker (respectively) to
instantiate any class on the classpath.
Users are recommended to upgrade
both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3
which fixes this issue.
Is CVE-2023-46604 exploited? Listed in the CISA KEV catalog on 2023-11-02. Federal remediation due 2023-11-23. Past that date by 1043 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 99.9%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? Atlassian · Bamboo · Data Center LTS <10.2.22 Atlassian · Bamboo · Data Center LTS <12.1.10 Atlassian · Jira · Data Center LTS <10.3.24 Atlassian · Bitbucket · Data Center <10.4.2 Dell · Secure Connect Gateway · <5.36.00.16 Atlassian · Bitbucket · Data Center LTS <9.4.23 Atlassian · Bitbucket · Data Center LTS <10.2.6 Atlassian · Confluence · Data Center LTS <9.2.23 Atlassian · Confluence · Data Center LTS <10.2.15 Atlassian · Fisheye · <4.9.13 Atlassian · Crucible · <4.9.13 Atlassian · Jira · Data Center LTS <11.3.10 Apache Software Foundation · Apache ActiveMQ · >= 5.18.0, < 5.18.3, >= 5.17.0, < 5.17.6, >= 5.16.0, < 5.16.7, >= 0, < 5.15.16 Apache Software Foundation · Apache ActiveMQ Legacy OpenWire Module · >= 5.18.0, < 5.18.3, >= 5.17.0, < 5.17.6, >= 5.16.0, < 5.16.7, >= 5.8.0, < 5.15.16 debian · debian linux · 10.0, 11.0 netapp · e-series santricity unified manager netapp · e-series santricity web services proxy netapp · santricity storage plugin Is there a patch? Bamboo Data Center LTS 10.2.22 Bamboo Data Center LTS 12.1.10 Jira Data Center LTS 10.3.24 Bitbucket Data Center 10.4.2 Secure Connect Gateway 5.36.00.16 Bitbucket Data Center LTS 9.4.23 Bitbucket Data Center LTS 10.2.6 Confluence Data Center LTS 9.2.23 Confluence Data Center LTS 10.2.15 Fisheye 4.9.13 Crucible 4.9.13 Jira Data Center LTS 11.3.10 What PlainSec published about CVE-2023-46604 Primary sources KEV and EPSS are re-checked daily. Record last updated 2026-10-01.