CVE-2016-0709
HIGHApache Jetspeed <2.3.1 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp."
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotejava
https://www.exploit-db.com/exploits/39643
References (6)
Scores
CVSS v3
7.2
EPSS
0.7090
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-22
Status
draft
Affected Products (2)
apache/jetspeed
< 2.3.0
org.apache.portals.jetspeed-2/jetspeed
< 2.3.1Maven
Timeline
Published
Apr 11, 2016
Tracked Since
Feb 18, 2026