← Vulnerability feed

Vulnerability record · CVE-2016-0710 · published 11 April 2016

CVE-2016-0710: Apache Jetspeed User Manager SQL injection

Apache · Jetspeed

Apache Jetspeed before 2.3.1 contains multiple SQL injection flaws in the User Manager service, reachable through the role and user parameters of services/usermanager/users/. An attacker who can reach that endpoint can inject arbitrary SQL, which matters because the vulnerable component is a portal service that may hold sensitive user and role data.

8.8 CVSS 3.0 High EPSS 52% · top 1.1% CWE-89 · SQL injection
8.8CVSS 3.0 base score, v2 7.5
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 8.8 with low privileges required, network reachability, and public exploit references make this a serious issue, though it is not in KEV and requires authentication.

What it is

Apache Jetspeed before 2.3.1 contains multiple SQL injection flaws in the User Manager service, reachable through the role and user parameters of services/usermanager/users/. An attacker who can reach that endpoint can inject arbitrary SQL, which matters because the vulnerable component is a portal service that may hold sensitive user and role data.

Impact

Successful exploitation lets an attacker execute arbitrary SQL commands against the backend database, enabling data theft or modification and potentially further compromise depending on database privileges.

Attack surface

The flaw is network-reachable via the User Manager HTTP endpoint (services/usermanager/users/) using the role or user parameter. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user is the likely entry point.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.52 (99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Apache Jetspeed to 2.3.1 or later, which the vendor advisory states fixes this issue.
  • If immediate upgrade is not possible, restrict network access to the User Manager service and require strong authentication for all users.
  • Apply input validation and parameterized queries or stored procedures to the role and user parameters as a compensating control.
  • Review database account privileges used by Jetspeed and reduce them to the minimum needed.
  • Monitor vendor and CVE feeds for any updated guidance on affected versions.

Detection

  • Inspect web and application logs for requests to services/usermanager/users/ containing SQL metacharacters or unusual role/user parameter values.
  • Enable database query logging and alert on anomalous SQL from the Jetspeed application account.
  • Use a WAF or IDS rule set to flag SQL injection patterns targeting the User Manager endpoint.
  • Baseline normal User Manager traffic and alert on deviations such as unexpected parameter lengths or encoding.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0710 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-32533Apache jetspeed cross-site scripting vulnerabilityApache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…EPSS 4.1%7.5CVE-2016-2171Apache jetspeed permissions and access controls vulnerabilityThe User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to …EPSS 43%7.2CVE-2016-0709Apache Jetspeed Portal Site Manager path traversal enables code executionThe Import/Export function in Apache Jetspeed's Portal Site Manager fails to sanitize ZIP archive entry names, allowing directory traversal via '..' …EPSS 77%analysed6.1CVE-2016-0712Apache jetspeed cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_…EPSS 3.2%6.1CVE-2016-0711Apache jetspeed cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via…EPSS 3.1%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed10.0CVE-2026-72898Metabase unauthenticated SQL injection in reset_password endpointMetabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because th…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2016-0710), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.