AI description
CVE-2016-3088 describes a vulnerability found in the Fileserver web application within Apache ActiveMQ versions 5.x prior to 5.14.0. This flaw allows remote attackers to upload and subsequently execute arbitrary files on the affected system. The attack vector involves a two-step process: an attacker first uses an HTTP PUT request to upload a malicious file, and then leverages an HTTP MOVE request to relocate the uploaded file to a directory where it can be executed.
- Description
- The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
- Products
- activemq
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Data from CISA
- Vulnerability name
- Apache ActiveMQ Improper Input Validation Vulnerability
- Exploit added on
- Feb 10, 2022
- Exploit action due
- Aug 10, 2022
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://t.co/NA37SY4GRO
@akaclandestine
8 Jun 2026
3906 Impressions
13 Retweets
49 Likes
30 Bookmarks
0 Replies
0 Quotes
⚠️ **Vulnerability Alert:** Apache ActiveMQ — Consolidated RCE and Jolokia/OpenWire/Fileserver issues (CVE-2026-34197 + CVE-2024-32114 + CVE-2022-41678 + CVE-2023-46604 + CVE-2016-3088) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: unknown 🆔 **CVE-2026-34197** |
@syedaquib77
7 Apr 2026
64 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D44743D6-E0CE-44B1-80CA-B760434FC850",
"versionEndExcluding": "5.14.0",
"versionStartIncluding": "5.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]