CVE-2016-3088

Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.294

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-3088 are fixed in Apache-activemq-client 5.14.0Windows
Multiple Vulnerabilities are affected in IBM Security Verify Directory Integrator 7.2.0Windows
Vulnerabilities CVE-2016-3088 are fixed in Apache-activemq-client for Linux 5.14.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234