Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2016-3088

Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to…

Technology

Apache ActiveMQ

CVSS Score

9.8 / 10.0

Affected Versions

>=5.0.0 <5.14.0

Upstream Fix

See upstream advisory

Published

June 1, 2016

OSSeva Coverage

Fixed upstream

Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

Is your Apache ActiveMQ deployment affected?

If you're running >=5.0.0 <5.14.0, you need this patch. Book a discovery call to get covered.