NCM 10.1.x
The file activemq-broker-5.16.4.jar, mentioned in CVE-2023-46604, resides in the following two NCM directories:
/opt/smarts-ncm/Transformation/lib/
/opt/smarts-ncm/cm/daemon/lib/The vulnerable component "OpenWire protocol" as mentioned in the CVE is not being used by NCM thus NCM is not impacted from this vulnerability.
As an alternative, we are using the tcp://<IP>:61616 transport connector, which corresponds to the OpenWire protocol in ActiveMQ. This protocol is used internally by ActiveMQ to communicate between the client and the broker.