CyberzSOC

Applicability
← Back to CVE-2023-46604

CVE-2023-46604

In CISA KEV Apache

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2025-11-21
1 affected 6 fixed
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-08
16 affected 16 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-11-03
8 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (47)

Product Status Versions Remediation Source
red_hat_jboss_fuse_service_works_6:activemq-openwire activemq-openwire as a component of Red Hat JBoss Fuse Service Works 6 affected no version stated vendor label: activemq-openwire out of support fix in another branch csaf_redhat
AMQ 6.3 openshift container image fixed no version stated vendor fix csaf_redhat
AMQ Broker 7.10.5 fixed no version stated vendor fix csaf_redhat
AMQ Broker 7.11.4 fixed no version stated vendor fix csaf_redhat
7Server-RHOSE-Middleware:jboss-amq-6/amq63-openshift@sha256:ee5a3799f9b610e014cd03c49ae15d4b39196de58e63ac340f7e559266a2d6ce_amd64 jboss-amq-6/amq63-openshift@sha256:ee5a3799f9b610e014cd03c49ae15d4b39196de58e63ac340f7e559266a2d6ce_amd64 as a component of Middleware RHEL 7 Containers for OpenShift fixed jboss-amq-6/amq63-openshift@sha256:ee5a3799f9b610e014cd03c49ae15d4b39196de58e63ac340f7e559266a2d6ce_amd64 vendor fix → jboss-amq-6/amq63-openshift@sha256:ee5a3799f9b610e014cd03c49ae15d4b39196de58e63ac340f7e559266a2d6ce_amd64 (RHSA-2023:6866) csaf_redhat
Red Hat Fuse 7.12.1 fixed no version stated vendor fix csaf_redhat
Red Hat Fuse/AMQ 6.3.20 fixed no version stated vendor fix csaf_redhat
activemq affected < 5.15.16 vendor fix → 5.15.16 osv BIT-activemq-2023-46604
activemq affected >= 5.16.0, < 5.16.7 vendor fix → 5.16.7 osv BIT-activemq-2023-46604
activemq affected >= 5.17.0, < 5.17.6 vendor fix → 5.17.6 osv BIT-activemq-2023-46604
activemq affected >= 5.18.0, < 5.18.3 vendor fix → 5.18.3 osv BIT-activemq-2023-46604
https://github.com/apache/activemq affected < 691e8f9e6d96dd58791f4fe9add7aead47677a67 vendor fix → 691e8f9e6d96dd58791f4fe9add7aead47677a67 osv
https://github.com/apache/activemq affected >= 86dd78b1aa64cbf0af15669c0e4af62dfae0d158, < 4bbb055187166706103d785e9665efb439792c51 vendor fix → 4bbb055187166706103d785e9665efb439792c51 osv
https://github.com/apache/activemq affected >= 1f3ccad9bb330cbd7468f9f10ac0b542e7f8b51b, < 4a25366541fed60b15b4a068f2d3018f533cdeb9 vendor fix → 4a25366541fed60b15b4a068f2d3018f533cdeb9 osv
https://github.com/apache/activemq affected >= f18f3223fab0d36f7928d2bb7ae488edf3c5bc12, < 5f6edd9781c1438aa40fd4c7ec243a76a6be38c0 vendor fix → 5f6edd9781c1438aa40fd4c7ec243a76a6be38c0 osv
org.apache.activemq:activemq-client affected < 5.15.16 vendor fix → 5.15.16 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-client affected >= 5.16.0, < 5.16.7 vendor fix → 5.16.7 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-client affected >= 5.17.0, < 5.17.6 vendor fix → 5.17.6 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-client affected >= 5.18.0, < 5.18.3 vendor fix → 5.18.3 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy affected >= 5.8.0, < 5.15.16 vendor fix → 5.15.16 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy affected >= 5.16.0, < 5.16.7 vendor fix → 5.16.7 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy affected >= 5.17.0, < 5.17.6 vendor fix → 5.17.6 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy affected >= 5.18.0, < 5.18.3 vendor fix → 5.18.3 osv GHSA-crg9-44h2-xw35
activemq fixed 5.15.16 vendor fix → 5.15.16 osv BIT-activemq-2023-46604
activemq fixed 5.16.7 vendor fix → 5.16.7 osv BIT-activemq-2023-46604
activemq fixed 5.17.6 vendor fix → 5.17.6 osv BIT-activemq-2023-46604
activemq fixed 5.18.3 vendor fix → 5.18.3 osv BIT-activemq-2023-46604
https://github.com/apache/activemq fixed 691e8f9e6d96dd58791f4fe9add7aead47677a67 vendor fix → 691e8f9e6d96dd58791f4fe9add7aead47677a67 osv
https://github.com/apache/activemq fixed 4bbb055187166706103d785e9665efb439792c51 vendor fix → 4bbb055187166706103d785e9665efb439792c51 osv
https://github.com/apache/activemq fixed 4a25366541fed60b15b4a068f2d3018f533cdeb9 vendor fix → 4a25366541fed60b15b4a068f2d3018f533cdeb9 osv
https://github.com/apache/activemq fixed 5f6edd9781c1438aa40fd4c7ec243a76a6be38c0 vendor fix → 5f6edd9781c1438aa40fd4c7ec243a76a6be38c0 osv
org.apache.activemq:activemq-client fixed 5.15.16 vendor fix → 5.15.16 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-client fixed 5.16.7 vendor fix → 5.16.7 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-client fixed 5.17.6 vendor fix → 5.17.6 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-client fixed 5.18.3 vendor fix → 5.18.3 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy fixed 5.15.16 vendor fix → 5.15.16 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy fixed 5.16.7 vendor fix → 5.16.7 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy fixed 5.17.6 vendor fix → 5.17.6 osv GHSA-crg9-44h2-xw35
org.apache.activemq:activemq-openwire-legacy fixed 5.18.3 vendor fix → 5.18.3 osv GHSA-crg9-44h2-xw35
Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:activemq-client Apache Software Foundation · Apache ActiveMQ affected >= 5.18.0, < 5.18.3 none available cve_cna
Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:activemq-client Apache Software Foundation · Apache ActiveMQ affected >= 5.17.0, < 5.17.6 none available cve_cna
Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:activemq-client Apache Software Foundation · Apache ActiveMQ affected >= 5.16.0, < 5.16.7 none available cve_cna
Apache Software Foundation/Apache ActiveMQ/org.apache.activemq:activemq-client Apache Software Foundation · Apache ActiveMQ affected < 5.15.16 none available cve_cna
Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module/org.apache.activemq:activemq-openwire-legacy Apache Software Foundation · Apache ActiveMQ Legacy OpenWire Module affected >= 5.18.0, < 5.18.3 none available cve_cna
Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module/org.apache.activemq:activemq-openwire-legacy Apache Software Foundation · Apache ActiveMQ Legacy OpenWire Module affected >= 5.17.0, < 5.17.6 none available cve_cna
Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module/org.apache.activemq:activemq-openwire-legacy Apache Software Foundation · Apache ActiveMQ Legacy OpenWire Module affected >= 5.16.0, < 5.16.7 none available cve_cna
Apache Software Foundation/Apache ActiveMQ Legacy OpenWire Module/org.apache.activemq:activemq-openwire-legacy Apache Software Foundation · Apache ActiveMQ Legacy OpenWire Module affected >= 5.8.0, < 5.15.16 none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.