Loading

Remote Code Execution (RCE) vulnerability impacting Apache ActiveMQ clients

Date de publication: Feb 18, 2025
Description

On November 2, 2023, Apache announced the discovery of CVE-2023-46604, a Remote Code Execution (RCE) vulnerability impacting Apache ActiveMQ clients.  As a result of this issue, a remote threat actor with network access to either a Java-based OpenWire broker or client could execute a RCE to run arbitrary shell commands.

 

We assigned the CVSSv3 score as 9.6. 


 

Résolution

On January 10, 2024, Tableau addressed this issue with Messaging Service and released new versions of Tableau Server below installed with the fix.

Tableau Server Versions(Issue got fixed) :
2022.3.12+,
2023.1.8+,
2023.3.1+.

 

Numéro d’article de la base de connaissances

001470727

 
Chargement
Salesforce Help | Article