Umbra Wiki cve cve/CVE-2016-3088
Back to wiki

CVE-2016-3088 — Apache ActiveMQ Improper Input Validation Vulnerability

provenance: imported · CVE: CVE-2016-3088 · CWE: CWE-20

CVE-2016-3088: Apache ActiveMQ Improper Input Validation Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Apache
Product ActiveMQ
Date added 2022-02-10
Due date 2022-08-10
Ransomware campaign use Unknown

Description

The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2016-3088

Weakness behind it

CISA records this vulnerability as an instance of CWE-20. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2016-3088
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →