CVE-2016-3088
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache ActiveMQ Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-434
מוצרים מושפעים
apache: activemq
קישורים
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement… Vendor Advisory
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2c… Mailing ListVendor Advisory
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement… Vendor Advisory
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2c… Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a… Mailing ListPatch
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a… Mailing ListPatch
- https://www.exploit-db.com/exploits/42283/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42283/ ExploitThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-2036.html Third Party Advisory
- http://www.securitytracker.com/id/1035951 Broken LinkThird Party AdvisoryVDB Entry