CVE-2015-1830: Apache ActiveMQ

Medium severity, CVSS 5.0. EPSS: 84.4% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

Affected products

  • Apache ActiveMQ: version 5.0.0 only; version 5.1.0 only; version 5.2.0 only; version 5.3.0 only; version 5.3.1 only; version 5.3.2 only; …

Published 2015-08-19. Last modified 2026-06-17.