FAIL › dossier
ActiveMQ
PRODUCT· dossier confidence 50%
ActiveMQ, an open-source messaging broker, has experienced significant security vulnerabilities, including remote code execution and file upload issues.
PROFILE
CategoryMessaging SoftwareWhat they doActiveMQ is an open-source message broker that enables the decoupling of distributed systems, often used for asynchronous communication.
SECURITY POSTURE
The company has faced multiple security vulnerabilities, indicating a need for continuous improvement in security practices.
Notable failures
- CVE-2023-46604: Remote code execution through deserialization vulnerability in OpenWire protocol
- CVE-2026-34197: Code injection vulnerability allowing remote code execution
- CVE-2016-3088: Arbitrary file upload and execution via HTTP PUT and MOVE requests
Patterns: Repeated deserialization vulnerabilities; Code injection vulnerabilities; File upload vulnerabilities
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-11-02 | CVE-2023-46604 | critical | A remote attacker could execute arbitrary shell commands on an Apache ActiveMQ broker by exploiting a deserialization vulnerability in the OpenWire protocol. |
| 2022-02-10 | CVE-2016-3088 | high | Apache ActiveMQ's Fileserver web app allowed remote attackers to upload and execute arbitrary files via HTTP PUT and MOVE requests. |
| 2026-04-16 | CVE-2026-34197 | high | Apache ActiveMQ exploited a code injection vulnerability (CVE-2026-34197) allowing remote code execution. |
Open questions: How has the company addressed these vulnerabilities? · What is the current state of security in the product?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:45:31.622167+00:00