CVE-2015-1830: Path Traversal
Apache ActiveMQ could allow a remote attacker to traverse directories on the system, caused by an error in the fileserver upload/download functionality. By placing a jsp file in the admin console, an attacker could exploit this vulnerability to execute arbitrary shell commands on the system.
Other sources
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-1830?
CVE-2015-1830 is a directory traversal vulnerability in Apache ActiveMQ that allows a remote attacker to execute arbitrary shell commands on the system.
What is the severity level of CVE-2015-1830?
CVE-2015-1830 has a severity level of 9.8, which is considered critical.
Which versions of Apache ActiveMQ are affected by CVE-2015-1830?
Apache ActiveMQ versions 5.0.0 to 5.11.1 are affected by CVE-2015-1830.
How can I fix CVE-2015-1830?
To fix CVE-2015-1830, it is recommended to upgrade to a patched version of Apache ActiveMQ.
Where can I find more information about CVE-2015-1830?
More information about CVE-2015-1830 can be found on the Apache ActiveMQ website and security advisory pages.