The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Activemq
APPApache5.0.0 – 5.14.0 (excl.)
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- ActiveMQ
- Added to KEVi
- February 10, 2022
- Remediation deadline (US Federal)i
- August 10, 2022(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 10 sierpnia 2022
References
Related vulnerabilities
CVE-2023-46604CRITICAL10.0⚠ KEVPL ✓same product
Apache ActiveMQ — RCE przez podatny marshaller protokołu OpenWire
CVE-2020-11998CRITICAL9.8PL ✓same product
Apache ActiveMQ — RCE przez błędną konfigurację JMX RMIConnectorServer
CVE-2013-7285CRITICAL9.8PL ✓same product
XStream RCE – wykonanie dowolnych poleceń przy deserializacji XML/JSON
CVE-2014-3600CRITICAL9.8PL ✓same product
XXE w Apache ActiveMQ 5.x — podatność przy przetwarzaniu wiadomości XML
CVE-2015-5254CRITICAL9.8PL ✓same product
Apache ActiveMQ — RCE przez deserializację obiektów JMS ObjectMessage