CVE-2016-3088 is a critical vulnerability affecting the Fileserver web application in Apache ActiveMQ versions prior to 5.14.0, allowing remote attackers to upload and execute arbitrary files. This vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with readily available exploit code in Metasploit and Nuclei, and has garnered significant community discussion and media coverage, indicating widespread awareness and potential for abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.14.0CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.