CVE-2016-0709: Apache Jetspeed
High severity, CVSS 7.2. EPSS: 77.5% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp."
Affected products
- Apache Jetspeed: up to and including 2.3.0
Published 2016-04-11. Last modified 2026-06-17.