CVE-2016-3088
apache activemq
Published 1 Jun 2016 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Feb 2022, with a remediation deadline of 10 Aug 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
References
- activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt · Vendor Advisory
- rhn.redhat.com/errata/RHSA-2016-2036.html · Third Party Advisory
- www.securitytracker.com/id/1035951 · Broken Link, Third Party Advisory, VDB Entry
- www.zerodayinitiative.com/advisories/ZDI-16-356 · Third Party Advisory, VDB Entry
- www.zerodayinitiative.com/advisories/ZDI-16-357 · Third Party Advisory, VDB Entry
- lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E · Mailing List, Patch
- lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3E · Issue Tracking, Mailing List
- lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E · Mailing List, Vendor Advisory
- www.exploit-db.com/exploits/42283/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3088 · US Government Resource