activemq: Fileserver web application vulnerability allowing RCE
Published Jun 1, 2016 ·Due Aug 10, 2022
9.8
CRITICALCVSS 3.1
EPSS 98.52%
Description
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Affected products
No data.
No data.
Red Hat JBoss A-MQ 6.3
n/a
Fixed · RHSA-2016:2036
Red Hat JBoss Fuse 6.2
n/a
Fixed · RHSA-2015:1176
Red Hat JBoss A-MQ 6
activemq
Affected
Red Hat JBoss Fuse 6
activemq
Affected
Red Hat JBoss Fuse Service Works 6
activemq
Not affected
Red Hat OpenShift Enterprise 2
activemq
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss A-MQ 6.3 | n/a | Fixed | RHSA-2016:2036 |
| Red Hat JBoss Fuse 6.2 | n/a | Fixed | RHSA-2015:1176 |
| Red Hat JBoss A-MQ 6 | activemq | Affected | n/a |
| Red Hat JBoss Fuse 6 | activemq | Affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | activemq | Not affected | n/a |
| Red Hat OpenShift Enterprise 2 | activemq | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat JBoss A-MQ 6.3 , Red Hat JBoss Fuse 6.3, and Red Hat JBoss Fuse Service Works 6.0.0 do not provide the vulnerable component and are not affected by this flaw. Red Hat JBoss A-MQ 6.2.1 and Red Hat JBoss Fuse 6.2.1 disable the vulnerable component and as such are not vulnerable to this flaw. The fileserver component was first disabled in A-MQ 6.2.0 and Fuse 6.2.0. Users of older, unsupported versions of these products are strongly advised to observe the mitigation provided on this page.
Red Hat mitigation
Users are advised to use other FTP and HTTP based file servers for transferring blob messages. Fileserver web application SHOULD NOT be used in older version of the broker and it should be disabled (it has been disabled by default since 5.12.0). This can be done by removing (commenting out) the following lines from conf\jetty.xml file <bean class="org.eclipse.jetty.webapp.WebAppContext"> <property name="contextPath" value="/fileserver" /> <property name="resourceBase" value="${activemq.home}/webapps/fileserver" /> <property name="logUrlOnStart" value="true" /> <property name="parentLoaderPriority" value="true" /> </bean>
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
Feb 10, 2022
Patch Due
Aug 10, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 98.52% (0.98518) | 99.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.52% (0.98518) | 99.91th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.34% (0.94339) | 99.95th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.73% (0.96733) | 99.72th | v3 (v2023.03.01) |
| Jul 25, 2024 | 96.66% (0.96658) | 99.67th | v3 (v2023.03.01) |
| Mar 7, 2023 | 83.95% (0.83955) | 97.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 94.47% (0.94469) | 99.95th | v2 (v2022.01.01) |
| Feb 4, 2022 | 94.47% (0.94469) | 99.94th | v2 (v2022.01.01) |
References (22)
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt x_refsource_CONFIRMVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2036.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securitytracker.com/id/1035951 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-356 x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-357 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2016-3088 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1339318 Issue Tracking
- https://github.com/advisories/GHSA-rxqh-fc23-gxp2 Advisory
- https://github.com/apache/activemq/commit/3dd86d04e8b90ba309819317d19e7260d414d9e7
- https://issues.apache.org/jira/browse/AMQ-6276
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLISTMailing ListPatch
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3E mailing-listx_refsource_MLISTIssue TrackingMailing List
- https://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a@%3Cusers.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLISTMailing ListVendor Advisory
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2016-3088
- https://stackoverflow.com/questions/67140241/configuring-activemq-webconsole-to-redirect-http-to-https
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3088 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2016-3088
- https://www.exploit-db.com/exploits/42283 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.