CVE-2016-3088

CRITICAL9.8⚠ KEVEPSS 94.3%

Improper Input Validation in Apache ActiveMQ

Published: 5/14/2022Modified: 4/28/2026Added to CISA KEV: 2/10/2022

Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H

References (18)