Maven package intelligence

org.apache.activemq:activemq-client Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.apache.activemq:activemq-client, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting org.apache.activemq:activemq-client
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.apache.activemq:activemq-client KEVs with sensor-observed exploitation activity

Review org.apache.activemq:activemq-client exploitation against the versions you run

All two exploited org.apache.activemq:activemq-client vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.apache.activemq:activemq-client vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2016-3088

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT...

In CISA 10 Feb 2022
CVE-2023-46604

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

In CISA 02 Nov 2023

Recurring weakness patterns

Unrestricted Upload of File with Dangerous Type and Deserialization of Untrusted Data account for mapped occurrences across this org.apache.activemq:activemq-client KEV portfolio.

Browse all KEVs →