CVE-2016-3088 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 98.5% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-08-10.
Description
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 98.52% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | yes — remediate by 2022-08-10 |
| Public exploit | yes |
| Published | 2016-06-01 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apache ActiveMQ Improper Input Validation Vulnerability |
|---|---|
| Added | 2022-02-10 |
| Due | 2022-08-10 |
| Vendor / product | Apache / ActiveMQ |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| apache | activemq |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit) | 2017-06-29 |
| exploit-db | Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution | 2015-08-17 |
References
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt
- http://rhn.redhat.com/errata/RHSA-2016-2036.html
- http://www.securitytracker.com/id/1035951
- http://www.zerodayinitiative.com/advisories/ZDI-16-356
- http://www.zerodayinitiative.com/advisories/ZDI-16-357
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- https://www.exploit-db.com/exploits/42283/
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt
- http://rhn.redhat.com/errata/RHSA-2016-2036.html
- http://www.securitytracker.com/id/1035951
- http://www.zerodayinitiative.com/advisories/ZDI-16-356
- http://www.zerodayinitiative.com/advisories/ZDI-16-357
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- https://www.exploit-db.com/exploits/42283/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3088
→ the Explorer · watch your stack · NVD