HTTP: Apache ActiveMQ Fileserver Directory Traversal

This signature detects attempts to exploit a known vulnerability against Apache ActiveMQ. This allows remote attackers to upload and execute arbitrary files.

Extended Description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

Affected Products

Apache activemq

Short Name
HTTP:APACHE:MUL-METHOD-DIRTRAV
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveMQ Apache CVE-2015-1499 CVE-2015-3435 CVE-2016-3088 Directory Fileserver Traversal
Release Date
06/21/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3796
False Positive
Unknown
Vendors

Apache

CVSS Score

7.5

8.5

10.0

Found a potential security threat?