PT-2015-2776 · Apache · Apache Activemq

Steven Seeley

·

Published

2015-08-19

·

Updated

2023-02-13

·

CVE-2015-1830

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions 5.x through 5.11.1
Description The issue exists due to incorrect restriction of the directory path name with limited access in the file server upload/download functionality of Apache ActiveMQ. This allows a remote attacker to create JSP files in arbitrary directories, potentially leading to remote code execution.
Recommendations For Apache ActiveMQ versions 5.x through 5.11.1, update to version 5.11.2 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2015-12141
CVE-2015-1830
GHSA-3V63-F83X-37X4
ZDI-15-407

Affected Products

Apache Activemq