OSSEVA FOR ACTIVEMQ CLASSIC
ActiveMQ Classic 5.x — still running, no longer patched.
Apache ships ActiveMQ Classic fixes on the current 5.19.x line and on 6.3.x. If your brokers are on 5.15, 5.16, 5.17 or 5.18 — and most long-lived estates are — the advisories keep coming and the patches do not. OSSeva backports them to the line you are on.
Last reviewed
Trusted globally by enterprises




Why now
Only the newest 5.x line receives fixes
Apache ActiveMQ Classic maintains the current 5.19.x series alongside 6.3.x; Apache lists 6.0, 6.1 and 6.2 as inactive. Releases continue steadily on those lines — 5.19.11 shipped on 5 September 2026 — but nothing is backported to 5.15, 5.16, 5.17 or 5.18. Those are the versions that shipped with a decade of enterprise integrations built on top of them.
CVE-2023-46604 proved how exposed this installed base is
The OpenWire unauthenticated remote code execution flaw was exploited in the wild by ransomware operators within days of disclosure. It affected every 5.x line below the patched releases. Organisations that could not upgrade on that timeline discovered exactly how little room a broker upgrade leaves you during an active incident.
The migration to Artemis is a rewrite, not an upgrade
ActiveMQ Artemis is a different broker with a different persistence engine, different clustering and different configuration. It is the right destination for most estates, but it is a project measured in quarters. Extended support on Classic is what makes that project a planned migration rather than an emergency one.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 5.15.x(No upstream fixes — OSSeva backported) | EOL | Clean |
| 5.16.x(No upstream fixes — OSSeva backported) | EOL | Clean |
| 5.17.x(No upstream fixes — OSSeva backported) | EOL | Clean |
| 5.18.x(No upstream fixes — OSSeva backported) | EOL | Clean |
| 5.19.x(Upstream maintained) | Current | Clean |
| 6.0–6.2.x(Apache lists as inactive — upgrade to 6.3.x) | EOL | Clean |
| 6.3.x(Upstream maintained) | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Backported CVE patches for ActiveMQ Classic 5.15–5.18.
- Security backports to your 5.x line, no version jump required
- OpenWire and STOMP transport CVE priority coverage
- Java deserialization and JMX exposure hardening
- Maven / Docker / tarball delivery
- Signed artifacts (GPG)
- Artemis migration assessment
- 24/7 managed operations
OSSeva Assure
Patch plus broker audit and a costed path to Artemis or RabbitMQ.
- Everything in Patch
- Transport connector and authentication audit
- KahaDB and LevelDB store integrity review
- Network-of-brokers topology review
- SOC 2 / HIPAA attestation package
- Artemis or RabbitMQ migration assessment
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 broker monitoring, 15-min SLA, named JMS engineers.
- Everything in Assure
- 24/7 queue depth, store usage and connection monitoring
- 15-minute P1 incident response SLA
- Named senior ActiveMQ engineer
- Dead letter queue and redelivery policy management
- Migration execution to Artemis or RabbitMQ
- Quarterly capacity planning reviews
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
# Version is reported on startup and via JMX
activemq --version
# Or from a running broker over Jolokia
curl -s -u admin:admin \
http://localhost:8161/api/jolokia/read/\
org.apache.activemq:type=Broker,brokerName=localhost/BrokerVersion
# Anything below 5.19 receives no upstream security fixes.<dependency>
<groupId>io.osseva.activemq</groupId>
<artifactId>activemq-broker</artifactId>
<version>5.17.6-osseva-1</version>
</dependency>
<dependency>
<groupId>io.osseva.activemq</groupId>
<artifactId>activemq-client</artifactId>
<version>5.17.6-osseva-1</version>
</dependency>Migrate from Unsupported ActiveMQ Classic 5.x lines
OSSeva backports upstream security fixes onto the 5.x line you are running, so brokers stay on a version your integrations, selectors and store format already work with. When you are ready to leave Classic, the same engagement covers assessment and execution of the move to ActiveMQ Artemis or RabbitMQ.
Pricing model
OSSeva for ActiveMQ Classic is priced per broker cluster — not per queue, connection or message volume.
Frequently asked questions
Is Apache ActiveMQ Classic 5.x end of life?
Not as a product line — the current 5.19.x series is actively maintained and released alongside 6.3.x. What is end of life is every older 5.x line. Apache does not backport security fixes to 5.15, 5.16, 5.17 or 5.18, so a broker on any of those receives nothing regardless of how many advisories are published against it.
What is the difference between ActiveMQ Classic and ActiveMQ Artemis?
They are two separate brokers under one project name. Classic is the original 5.x broker with KahaDB persistence and the OpenWire protocol at its centre. Artemis is a newer high-performance broker donated from HornetQ, with its own journal, its own clustering model and its own configuration format. Moving between them is a migration, not an upgrade — which is why OSSeva covers both.
Does OSSeva patch CVE-2023-46604?
Yes, and it is the clearest illustration of the gap this service exists to close. That OpenWire flaw allowed unauthenticated remote code execution and was exploited by ransomware groups within days of disclosure. OSSeva ships the fix backported onto 5.15 through 5.18 so brokers that cannot take a version jump are still protected.
Can we stay on ActiveMQ Classic indefinitely?
Under OSSeva coverage, yes — but we will not pretend that is the better long-term answer. Classic is in maintenance upstream and the ecosystem investment is going into Artemis. The honest recommendation for most estates is extended support now and a planned migration over the following twelve to eighteen months, with OSSeva carrying the security risk in the meantime.
Do you support the JMS client libraries as well as the broker?
Yes. The activemq-client artifact ships inside applications, not just on broker hosts, and deserialization advisories frequently land on the client side. OSSeva publishes patched client and broker artifacts from the same build so the versions on both ends of a connection stay matched.
Ready to get Apache ActiveMQ Classic patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.