PT-2016-3434 · Apache · Apache Activemq
Hillary Benson
+1
·
Publicado
2016-05-24
·
Atualizado
2026-06-09
·
CVE-2016-3088
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ versions 5.x through 5.13.x
Description
The issue exists due to insufficient input validation in the Fileserver web application. It allows a remote attacker to upload and execute arbitrary files via an HTTP PUT request followed by an HTTP MOVE request. This can be achieved by sending a
PUT request to a vulnerable endpoint, such as /fileserver, and then sending a MOVE request to execute the uploaded file.Recommendations
For Apache ActiveMQ versions 5.x through 5.13.x, update to version 5.14.0 or later to resolve the issue.
As a temporary workaround, consider disabling the HTTP MOVE method for the Fileserver web application until a patch is available.
Restrict access to the Fileserver web application to minimize the risk of exploitation.
Exploit
Correção
RCE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Activemq