Junglewise Threat Intelligence

CVE-2016-3088: Apache ActiveMQ Improper Input Validation Vulnerability

CVE-2016-3088 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-02-10

Technologies: Apache ActiveMQ. Vendors: Apache.

Executive brief

The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files. This is achieved by sending an HTTP PUT request to upload a file followed by an HTTP MOVE request to relocate it to an executable location.

Affected products

  • Apache ActiveMQ 5.x before 5.14.0

Timeline

  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-10: disclosed: NVD publication date
  • 2016-05-31: other: Security tracker ID 1035951 indicates 2016 activity

Related threats