← Back to browse · API

CVE-2016-3088

Severity
CRITICAL
CVSS
9.8
EPSS
0.98518
Risk score
59.48
CISA KEV
Yes
PoC
No
Published
2016-06-01
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-5255, GHSA-RXQH-FC23-GXP2
Products
Apache:ActiveMQ, n/a:n/a n/a
Sources
cisa.gov CVE-2016-3088
euvd EUVD-2022-5255

Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

References