Apache ActiveMQ Blob Message Directory Traversal

medium Nessus Plugin ID 85580


A web application on the remote host is affected by a directory traversal vulnerability.


The version of Apache ActiveMQ running on the remote host is affected by a directory traversal vulnerability due to improper sanitization of user-supplied input in the fileserver upload and download functionality. An unauthenticated, remote attacker can exploit this, via a specially crafted request, to read and upload arbitrary JSP files, resulting in the execution of arbitrary commands.


Upgrade to Apache ActiveMQ 5.11.2 / 5.12.0 or later. Alternatively, apply the vendor recommended mitigation instructions.

See Also


Plugin Details

Severity: Medium

ID: 85580

File Name: activemq_fileserver_directory_traversal.nasl

Version: 1.10

Type: remote

Family: CGI abuses

Published: 8/21/2015

Updated: 4/11/2022

Configuration: Enable thorough checks

Risk Information


Risk Factor: Medium

Score: 5.9


Risk Factor: Medium

Base Score: 5

Temporal Score: 4.1

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Temporal Vector: E:F/RL:OF/RC:ND

CVSS Score Source: CVE-2015-1830

Vulnerability Information

CPE: cpe:/a:apache:activemq

Required KB Items: installed_sw/ActiveMQ

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/17/2015

Vulnerability Publication Date: 8/17/2015

Exploitable With

Core Impact

Reference Information

CVE: CVE-2015-1830