CVE-2016-3088
published 2016-06-01CVE-2016-3088: The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-08-10
Exploited in the wild
EPSS
98.52%
99.9th percentile
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | >= 0 < 5.14.0+dfsg-1 | 5.14.0+dfsg-1 |
| apache | activemq | >= 0 < 5.14.0+dfsg-1 | 5.14.0+dfsg-1 |
| apache | activemq | >= 0 < 5.14.0+dfsg-1 | 5.14.0+dfsg-1 |
| apache | activemq | >= 5.0.0 < 5.14.0 | 5.14.0 |
| debian | activemq | < activemq 5.14.0+dfsg-1 (bookworm) | activemq 5.14.0+dfsg-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2016-3088 exploitation uses an HTTP PUT request to upload a file to the ActiveMQ Fileserver web application, followed by an HTTP MOVE request to relocate and execute it. Detect sequences of PUT+MOVE HTTP methods targeting ActiveMQ Fileserver endpoints. ↗
- →Pro-Ocean (Rocke Group) exploits CVE-2016-3088 on Apache ActiveMQ as part of its worm infection module. Look for exploitation attempts against ActiveMQ instances followed by download of a shell installation script from shop.168bee[.]com. ↗
- →Presence of /etc/ld.so.preload modified by malware (Pro-Ocean rootkit) is a strong post-exploitation indicator on Linux systems targeted via CVE-2016-3088. ↗
- →Xbash also fetches scanning targets via C2 URIs /domain/phpmyadmin, /domain/all, /port/tcp8080, /port/udp1900, and /cidir. Detect HTTP requests matching these URI patterns to external hosts as potential C2 beaconing. ↗
- →Pro-Ocean binary is UPX-packed with the UPX magic string deleted to evade static analysis. Detection tools should not rely solely on UPX header identification; use behavioral or memory-based detection. ↗
- →Xbash fetches C2 domain lists from Pastebin. Monitor for HTTP requests to Pastebin from ActiveMQ or other server processes as a potential indicator of compromise. ↗
- ·CVE-2016-3088 only affects Apache ActiveMQ 5.x versions before 5.14.0. Systems running 5.14.0 or later are not vulnerable via this specific attack vector. ↗
- ·Pro-Ocean's exploit list is not static — the malware downloads its infection payload from a remote server, so additional exploits beyond CVE-2016-3088 may be added dynamically by the attacker. ↗
- ·Pro-Ocean actively uninstalls Alibaba Cloud and Tencent Cloud monitoring agents, meaning agent-based cloud security solutions on these platforms may not detect or alert on the compromise. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload unrestricted upload (RHSA-2016:2036 / EDB-42283)
vuldb·2026-04-23·CVSS 9.8
CVE-2016-3088 [CRITICAL] Apache ActiveMQ up to 5.13.x Fileserver Web Application Upload unrestricted upload (RHSA-2016:2036 / EDB-42283)
A vulnerability was found in Apache ActiveMQ up to 5.13.x. It has been classified as critical. This impacts an unknown function of the component Fileserver Web Application. The manipulation leads to unrestricted upload (Upload).
This vulnerability is documented as CVE-2016-3088. The attack can be initiated remotely. Additionally, an exploit exists.
Upgrading the affected component is recommended.
GHSA
Improper Input Validation in Apache ActiveMQ
ghsa·2022-05-14
CVE-2016-3088 [CRITICAL] CWE-20 Improper Input Validation in Apache ActiveMQ
Improper Input Validation in Apache ActiveMQ
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
OSV
Improper Input Validation in Apache ActiveMQ
osv·2022-05-14
CVE-2016-3088 [CRITICAL] Improper Input Validation in Apache ActiveMQ
Improper Input Validation in Apache ActiveMQ
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
OSV
CVE-2016-3088: The Fileserver web application in Apache ActiveMQ 5
osv·2016-06-01·CVSS 9.8
CVE-2016-3088 [CRITICAL] CVE-2016-3088: The Fileserver web application in Apache ActiveMQ 5
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
VulnCheck
Apache ActiveMQ Improper Input Validation Vulnerability
vulncheck·2016·CVSS 9.8
CVE-2016-3088 [CRITICAL] CWE-20 Apache ActiveMQ Improper Input Validation Vulnerability
Apache ActiveMQ Improper Input Validation Vulnerability
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
Affected: Apache ActiveMQ
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.tenable.com/blog/xbash-malware-targets-windows-and-linux-with-ransomware-and-cryptomining; https://web.archive.org/web/20220227045141/https://risksense.com/wp-content/uploads/2019/09/RiskSense-Spotlight-Report-Ransomware.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.ivanti.com/resources/v/doc/pr-survey-report/ransomware-quarterly-indexreport_q2-q3; https://dashboa
CISA
Apache ActiveMQ Improper Input Validation Vulnerability
cisa·2022-02-10·CVSS 9.8
CVE-2016-3088 [CRITICAL] CWE-20 Apache ActiveMQ Improper Input Validation Vulnerability
Vulnerability: Apache ActiveMQ Improper Input Validation Vulnerability
Affected: Apache ActiveMQ
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-3088
Remediation Due Date: 2022-08-10
Red Hat
activemq: Fileserver web application vulnerability allowing RCE
vendor_redhat·2016-05-24·CVSS 9.8
CVE-2016-3088 [CRITICAL] CWE-22 activemq: Fileserver web application vulnerability allowing RCE
activemq: Fileserver web application vulnerability allowing RCE
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Statement: Red Hat JBoss A-MQ 6.3 , Red Hat JBoss Fuse 6.3, and Red Hat JBoss Fuse Service Works 6.0.0 do not provide the vulnerable component and are not affected by this flaw. Red Hat JBoss A-MQ 6.2.1 and Red Hat JBoss Fuse 6.2.1 disable the vulnerable component and as such are not vulnerable to this flaw. The fileserver component was first disabled in A-MQ 6.2.0 and Fuse 6.2.0. Users of older, unsupported versions of these products are strongly advised to observe the mitigation provided on this page.
Mitigation: Users are advised to use other F
Debian
CVE-2016-3088: activemq - The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remot...
vendor_debian·2016·CVSS 9.8
CVE-2016-3088 [CRITICAL] CVE-2016-3088: activemq - The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remot...
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Scope: local
bookworm: resolved (fixed in 5.14.0+dfsg-1)
bullseye: resolved (fixed in 5.14.0+dfsg-1)
sid: resolved (fixed in 5.14.0+dfsg-1)
trixie: resolved (fixed in 5.14.0+dfsg-1)
Suricata
ET WEB_SPECIFIC_APPS Apache ActiveMQ File Upload RCE (CVE-2016-3088)
suricata·2018-05-10·CVSS 9.8
CVE-2016-3088 [CRITICAL] ET WEB_SPECIFIC_APPS Apache ActiveMQ File Upload RCE (CVE-2016-3088)
ET WEB_SPECIFIC_APPS Apache ActiveMQ File Upload RCE (CVE-2016-3088)
Rule: alert http any any -> $HTTP_SERVERS 8161 (msg:"ET WEB_SPECIFIC_APPS Apache ActiveMQ File Upload RCE (CVE-2016-3088)"; flow:established,to_server; http.method; content:"MOVE"; http.header_names; to_lowercase; content:"|0d 0a|destination|0d 0a|"; fast_pattern; reference:cve,2016-3088; reference:url,www.exploit-db.com/exploits/42283/; classtype:attempted-admin; sid:2025574; rev:4; metadata:attack_target Web_Server, created_at 2018_05_10, cve CVE_2016_3088, deployment Datacenter, signature_severity Minor, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_20;)
Exploit-DB
ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)
exploitdb·2017-06-29·CVSS 9.8
CVE-2016-3088 [CRITICAL] ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)
ActiveMQ 'ActiveMQ web shell upload',
'Description' => %q(
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0
allows remote attackers to upload and execute arbitrary files via an
HTTP PUT followed by an HTTP MOVE request.
),
'Author' => [ 'Ian Anderson ', 'Hillary Benson ' ],
'License' => MSF_LICENSE,
'References' =>
[
[ 'CVE', '2016-3088' ],
[ 'URL', 'http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt' ]
],
'Privileged' => true,
'Platform' => %w{ java linux win },
'Targets' =>
[
[ 'Java Universal',
{
'Platform' => 'java',
'Arch' => ARCH_JAVA
}
],
[ 'Linux',
{
'Platform' => 'linux',
'Arch' => ARCH_X86
}
],
[ 'Windows',
{
'Platform' => 'win',
'Arch' => ARCH_X86
}
]
],
'DisclosureDate' => "Jun 01 2016",
'DefaultTarget' => 0))
register_options(
Exploit-DB
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
exploitdb·2015-08-17
CVE-2016-3088 Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
---
I have recently been playing with Apache ActiveMQ, and came across a simple but interesting directory traversal flaw in the fileserver upload/download functionality.
I have only been able to reproduce this on Windows, i.e. where "\" is a path delimiter.
An attacker could use this flaw to upload arbitrary files to the server, including a JSP shell, leading to remote code execution.
Exploiting Windows systems to achieve RCE The default conf/jetty.xml includes:
Effectively blocking the upload of JSP files into contexts that will allow them to execute.
I imagine there are many ways around this; for my proof of concept I opted to overwrite conf/jetty-realm.properties and set my own credentials:
$ cat jetty-rea
Metasploit
ActiveMQ web shell upload
metasploit
ActiveMQ web shell upload
ActiveMQ web shell upload
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Nuclei
Apache ActiveMQ Fileserver - Arbitrary File Write
nuclei·CVSS 9.8
CVE-2016-3088 [CRITICAL] Apache ActiveMQ Fileserver - Arbitrary File Write
Apache ActiveMQ Fileserver - Arbitrary File Write
Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request via the Fileserver web application.
Template:
id: CVE-2016-3088
info:
name: Apache ActiveMQ Fileserver - Arbitrary File Write
author: fq_hsu
severity: critical
description: Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request via the Fileserver web application.
impact: |
An attacker can write arbitrary files on the server, potentially leading to remote code execution.
remediation: |
Upgrade to Apache ActiveMQ version 5.14.0 or later to fix the vulnerability.
reference:
- https://www.exploit-db.com/exploi
Bleepingcomputer
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
blogs_bleepingcomputer·2026-04-21·CVSS 8.8
CVE-2026-34197 [HIGH] Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
## Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
## Sergiu Gatlan
Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability.
Apache ActiveMQ is the most popular open-source multi-protocol message broker for asynchronous communication between Java applications.
Tracked as CVE-2026-34197 , the vulnerability was discovered by Horizon3 researcher Naveen Sunkavally using the Claude AI assistant after remaining undetected for 13 years .
As Sunkavally explained, this security flaw stems from an improper input validation weakness that enables authenticated threat actors to execute arbitrary code on unpatched systems. The Apache maintainers h
Bleepingcomputer
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
blogs_bleepingcomputer·2026-04-17·CVSS 8.8
CVE-2026-34197 [HIGH] CISA flags Apache ActiveMQ flaw as actively exploited in attacks
## CISA flags Apache ActiveMQ flaw as actively exploited in attacks
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned on Thursday that a high-severity Apache ActiveMQ vulnerability patched earlier this month is now actively exploited in attacks.
Apache ActiveMQ is the most popular open-source Java-based message broker for asynchronous communication between applications.
Tracked as CVE-2026-34197 , the security flaw has gone undetected for 13 years and was discovered by Horizon3 researcher Naveen Sunkavally using the Claude AI assistant.
Sunkavally explained that the vulnerability stems from improper input validation, which allows authenticated threat actors to execute arbitrary code via injection attacks. The Apache maintainers patched the vulner
Bleepingcomputer
13-year-old bug in ActiveMQ lets hackers remotely execute commands
blogs_bleepingcomputer·2026-04-08·CVSS 8.5
CVE-2026-34197 [HIGH] 13-year-old bug in ActiveMQ lets hackers remotely execute commands
## 13-year-old bug in ActiveMQ lets hackers remotely execute commands
## Bill Toulas
This is also the reason why it was missed for more than a decade.
Apache ActiveMQ is an open-source message broker written in Java that handles asynchronous communication via message queues or topics.
Although ActiveMQ has released a newer ‘Artemis’ branch with better performance, the ‘Classic’ edition impacted by CVE-2026-34197 is widely deployed in enterprise, web backends, government, and company systems built on Java.
Horizon3 researcher Naveen Sunkavally found the issue "with nothing more than a couple of basic prompts" in Claude. "This was 80% Claude with 20% gift-wrapping by a human," he said.
Sunkavally notes that Claude pointed to the issue after examining multiple individual components (Jol
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Unit42
Pro-Ocean: Rocke Group’s New Cryptojacking Malware
blogs_unit42·2021-01-28·CVSS 9.8
[CRITICAL] Pro-Ocean: Rocke Group’s New Cryptojacking Malware
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## Pro-Ocean: Rocke Group’s New Cryptojacking Malware
Aviv Sasson
Published: January 28, 2021
Cloud Cybersecurity Research
Malware
Threat Research
Cryptocurrency
Monero
Rocke
## Executive Summary
In 2019, Unit 42 researchers documented cloud-targeted malware used by the Rocke Group to conduct cryptojacking attacks to mine for Monero. Since then, cybersecurity companies have had the malware on their radar, which hampered Rocke Group’s cryptojacking operation. In response, the threat actors updated the malware.
Here, we uncover a revised version of the same cloud-targeted cryptojacking malware, which now includes new and improved rootkit and worm capabilities. We also detail the hiding techniques used by th
Unit42
Pro-Ocean: Rocke Group’s New Cryptojacking Malware
blogs_unit42·2021-01-28·CVSS 9.8
[CRITICAL] Pro-Ocean: Rocke Group’s New Cryptojacking Malware
## Executive Summary
In 2019, Unit 42 researchers documented cloud-targeted malware used by the Rocke Group to conduct cryptojacking attacks to mine for Monero. Since then, cybersecurity companies have had the malware on their radar, which hampered Rocke Group’s cryptojacking operation. In response, the threat actors updated the malware.
Here, we uncover a revised version of the same cloud-targeted cryptojacking malware, which now includes new and improved rootkit and worm capabilities. We also detail the hiding techniques used by the malware to dodge cybersecurity companies’ detection methods, while explaining its four-module structure. We’ve named the malware Pro-Ocean after the name the attacker chose for the installation script.
Pro-Ocean uses known vulnerabilities to target cloud a
Checkpoint
SpeakUp: A New Undetected Backdoor Linux Trojan
blogs_checkpoint·2019-02-04
CVE-2018-20062 SpeakUp: A New Undetected Backdoor Linux Trojan
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## SpeakUp: A New Undetected Backdoor Linux Trojan
Check Point Research has discovered a new campaign exploiting Linux servers to implant a new Backdoor Trojan.
Dubbed ‘SpeakUp’, the new Tro
Tenable
Xbash Malware Targets Windows and Linux with Ransomware and Cryptomining
blogs_tenable·2018-09-19·CVSS 9.8
[CRITICAL] Xbash Malware Targets Windows and Linux with Ransomware and Cryptomining
Blog / Cyber Exposure Alerts
Subscribe
# Xbash Malware Targets Windows and Linux with Ransomware and Cryptomining
Satnam Narang
September 19, 2018
2 Min Read
Newly identified Xbash malware is targeting weak passwords and unpatched vulnerabilities on Linux and Windows systems to launch ransomware or cryptomining attacks.
## Background
Unit 42, Palo Alto Network’s research team, recently blogged about a new malicious software (malware) family it’s calling Xbash. This newly identified malware targets Linux and Windows systems that have weak passwords and unpatched vulnerabilities.
On Linux systems, Xbash will identify and delete MySQL, MongoDB and PostgreSQL databases and then seek ransom payment from victims. On Windows systems, it will initiate cryptomining and self-propagate. Organ
Tenable
Xbash Malware Targets Windows and Linux with Ransomware and Cryptomining
blogs_tenable·2018-09-19
Xbash Malware Targets Windows and Linux with Ransomware and Cryptomining
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
blogs_unit42·2018-09-17
Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
Threat Research Center
Threat Research
Malware
## Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
Claud Xiao
Cong Zheng
Xingyu Jin
Published: September 17, 2018
Cybercrime
Malware
Threat Research
ActiveMQ
Apple
Bitcoin
Botnet
CouchDB
Cryptocurrency
Elasticsearch
Hadoop
Iron
Linux
MacOS
Microsoft Windows
MongoDB
MySQL
Oracle
PostgreSQL
RDP
Redis
Rocke
Worm
Xbash
Executive Summary:
Unit 42 researchers have found a new malware family that is targeting Linux and Microsoft Windows servers that we have named XBash. We can tie this malware to the Iron Group, a threat actor group known for ransomware attacks in the past.
Xbash has ransomware and coinmining capabilities.
It also has self-propagating capabilities (meaning it h
Unit42
Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
blogs_unit42·2018-09-17
Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
Executive Summary:
Unit 42 researchers have found a new malware family that is targeting Linux and Microsoft Windows servers that we have named XBash. We can tie this malware to the Iron Group, a threat actor group known for ransomware attacks in the past.
Xbash has ransomware and coinmining capabilities.
It also has self-propagating capabilities (meaning it has worm-like characteristics similar to WannaCry or Petya/NotPetya). It also has capabilities not currently implemented that, when implemented, could enable it to spread very quickly within an organizations’ network (again, much like WannaCry or Petya/NotPetya).
Xbash spreads by attacking weak passwords and unpatched vulnerabilities.
Xbash is data-destructive; destroying Linux-based databases as part of its ransomware capabilitie
Bugzilla
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE [fedora-all]
bugzilla·2016-05-24·CVSS 9.8
CVE-2016-3088 [CRITICAL] CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE [fedora-all]
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
bugzilla·2016-05-24·CVSS 5.0
CVE-2016-3088 [MEDIUM] CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
Multiple vulnerabilities have been identified in the Apache ActiveMQ Fileserver web application. These are similar to those reported in CVE-2015-1830 and can allow attackers to replace web application files with malicious code and perform remote code execution on the system.
Mitigation:
Users are advised to use other FTP and HTTP based file servers for transferring blob messages. Fileserver web application SHOULD NOT be used in older version of the broker and it should be disabled (it has been disabled by default since 5.12.0). This can be done by removing (commenting out) the following lines from conf\jetty.xml file
External Reference:
http://activemq.apache.org/security-advisories.data/CVE-2016-3088
http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txthttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://www.securitytracker.com/id/1035951http://www.zerodayinitiative.com/advisories/ZDI-16-356http://www.zerodayinitiative.com/advisories/ZDI-16-357https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://www.exploit-db.com/exploits/42283/http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txthttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://www.securitytracker.com/id/1035951http://www.zerodayinitiative.com/advisories/ZDI-16-356http://www.zerodayinitiative.com/advisories/ZDI-16-357https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/f956ea38e4da2e2c1e7131e6f91e41754852f5a4861d1a14ca5ca78a%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://www.exploit-db.com/exploits/42283/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3088
2016-06-01
Published
2022-02-10
Added to CISA KEV
Exploited in the wild