CVE-2016-3088

critical Apache ⚠️ CISA KEV — Exploited in the Wild
CVSS v3 Base Score
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
94.2%
Exploitation probability in 30 days
Top 0% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: June 1, 2016 (3633 days ago)
Last Modified: April 21, 2026
Vendor: Apache
Source: NVD

⚠️ CISA Known Exploited Vulnerability

Added to KEV: 2022-02-10
Remediation Due: 2022-08-10 (⚠ 1373d overdue)

Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

CWE

CWE-434

Affected Products

apache activemq

References