CVE-2016-3088
CRITICAL9.8⚠ KEVEPSS 94.3%Improper Input Validation in Apache ActiveMQ
Published: 5/14/2022Modified: 4/28/2026Added to CISA KEV: 2/10/2022
Description
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Affected packages (2)
- Debian/activemqfrom 0, < 5.14.0+dfsg-1
- Maven/org.apache.activemq:activemq-client>= 5.0.0, < 5.14.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H |
References (18)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-3088
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2016-3088
- WEBhttp://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt
- WEBhttp://rhn.redhat.com/errata/RHSA-2016-2036.html
- WEBhttps://github.com/apache/activemq/commit/3dd86d04e8b90ba309819317d19e7260d414d9e7
- WEBhttps://issues.apache.org/jira/browse/AMQ-6276
- WEBhttps://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a@%3Cusers.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- WEBhttps://stackoverflow.com/questions/67140241/configuring-activemq-webconsole-to-redirect-http-to-https
- WEBhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3088
- WEBhttps://www.exploit-db.com/exploits/42283
- WEBhttp://www.securitytracker.com/id/1035951
- WEBhttp://www.zerodayinitiative.com/advisories/ZDI-16-356
- WEBhttp://www.zerodayinitiative.com/advisories/ZDI-16-357