First published: Wed Jun 01 2016(Updated: )
Apache ActiveMQ could allow a remote attacker to execute arbitrary code on the system, caused by an error in the Fileserver web application. By sending a specially crafted HTTP PUT request and an HTTP MOVE request, an attacker could exploit this vulnerability to create an arbitrary file and execute arbitrary code on the system.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ActiveMQ | <=5.13.3 | |
Apache ActiveMQ | >=5.0.0<5.14.0 | |
maven/org.apache.activemq:activemq-client | >=5.0.0<5.14.0 | 5.14.0 |
IBM Security Directory Suite VA | <=8.0.1-8.0.1.19 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3088 is a vulnerability in Apache ActiveMQ that allows a remote attacker to execute arbitrary code on the system.
CVE-2016-3088 is caused by an error in the Fileserver web application of Apache ActiveMQ. By sending a specially crafted HTTP PUT request and an HTTP MOVE request, an attacker can exploit this vulnerability to create an arbitrary file and execute arbitrary code.
CVE-2016-3088 has a severity rating of 9.8 out of 10, which is considered critical.
Apache ActiveMQ versions up to and including 5.13.3 are affected by CVE-2016-3088. IBM Security Directory Suite VA versions up to and including 8.0.1.19 are also affected.
To mitigate CVE-2016-3088, users should upgrade to a fixed version of Apache ActiveMQ or IBM Security Directory Suite VA.