← All CVEs

CVE-2015-1830

medium · 5

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

5
CVSS
84.4%
EPSS (exploit prob.)
100th
EPSS percentile
2015-08-19
Published

AV:N/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
apacheactivemq5.0.0
apacheactivemq5.1.0
apacheactivemq5.2.0
apacheactivemq5.3.0
apacheactivemq5.3.1
apacheactivemq5.3.2
apacheactivemq5.4.0
apacheactivemq5.4.1
apacheactivemq5.4.2
apacheactivemq5.4.3
apacheactivemq5.5.0
apacheactivemq5.5.1
apacheactivemq5.6.0
apacheactivemq5.7.0
apacheactivemq5.8.0
apacheactivemq5.9.0
apacheactivemq5.9.1
apacheactivemq5.10.0
apacheactivemq5.10.1
apacheactivemq5.10.2
apacheactivemq5.11.0
apacheactivemq5.11.1
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-1830