CISA Known Exploited Vulnerability

CVE-2016-3088

Apache · ActiveMQ

Apache ActiveMQ Improper Input Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request

Required action

Apply updates per vendor instructions.