peter bassill · operator
$ cve CVE-2016-3088 JSON

CVE-2016-3088 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 98.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-08-10.

Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS98.52% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVyes — remediate by 2022-08-10
Public exploityes
Published2016-06-01
Last modified2026-06-17

CISA KEV

NameApache ActiveMQ Improper Input Validation Vulnerability
Added2022-02-10
Due2022-08-10
Vendor / productApache / ActiveMQ
Ransomware usenone reported

Affected (1)

VendorProduct
apacheactivemq

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD