VulnerabilityAnalyzed
CVE-2016-3088
Apache ActiveMQ Improper Input Validation Vulnerability
KEVCRITICAL 9.8EPSS 98.5%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 August 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.52% probability · 100th percentile
- CISA KEV
- Listed 10 February 2022 · due 10 August 2022
- Weakness
- CWE-434
- Affected
- apache/activemq
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-3088
References
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2036.htmlThird Party Advisory
- http://www.securitytracker.com/id/1035951Broken Link, Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-356Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-357Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3EIssue Tracking, Mailing List
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3EMailing List, Vendor Advisory
- https://www.exploit-db.com/exploits/42283/Exploit, Third Party Advisory, VDB Entry
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2036.htmlThird Party Advisory
- http://www.securitytracker.com/id/1035951Broken Link, Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-356Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-357Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3EIssue Tracking, Mailing List
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3EMailing List, Vendor Advisory
- https://www.exploit-db.com/exploits/42283/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3088US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.