SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-3088

Apache ActiveMQ Improper Input Validation Vulnerability

KEVCRITICAL 9.8EPSS 98.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 August 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
98.52% probability · 100th percentile
CISA KEV
Listed 10 February 2022 · due 10 August 2022
Weakness
CWE-434
Affected
apache/activemq
Source
secalert@redhat.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-3088

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.