Executive brief
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files. This is achieved by sending an HTTP PUT request to upload a file followed by an HTTP MOVE request to relocate it to an executable location.
Affected products
- Apache ActiveMQ 5.x before 5.14.0
Timeline
- 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-10: disclosed: NVD publication date
- 2016-05-31: other: Security tracker ID 1035951 indicates 2016 activity