Vulnerability Description
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Activemq | >= 5.0.0, < 5.14.0 |
Related Weaknesses (CWE)
References
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.tVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2036.htmlThird Party Advisory
- http://www.securitytracker.com/id/1035951Broken LinkThird Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-356Third Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-357Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65Mailing ListPatch
- https://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861Issue TrackingMailing List
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0Mailing ListVendor Advisory
- https://www.exploit-db.com/exploits/42283/ExploitThird Party AdvisoryVDB Entry
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.tVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2036.htmlThird Party Advisory
- http://www.securitytracker.com/id/1035951Broken LinkThird Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-356Third Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-357Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65Mailing ListPatch
FAQ
What is CVE-2016-3088?
CVE-2016-3088 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
How severe is CVE-2016-3088?
CVE-2016-3088 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-3088?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Activemq.