Vulnerability record · CVE-2016-0710 · published 11 April 2016
CVE-2016-0710: Apache Jetspeed User Manager SQL injection
Apache · Jetspeed
Apache Jetspeed before 2.3.1 contains multiple SQL injection flaws in the User Manager service, reachable through the role and user parameters of services/usermanager/users/. An attacker who can reach that endpoint can inject arbitrary SQL, which matters because the vulnerable component is a portal service that may hold sensitive user and role data.
Description
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low privileges required, network reachability, and public exploit references make this a serious issue, though it is not in KEV and requires authentication.
What it is
Apache Jetspeed before 2.3.1 contains multiple SQL injection flaws in the User Manager service, reachable through the role and user parameters of services/usermanager/users/. An attacker who can reach that endpoint can inject arbitrary SQL, which matters because the vulnerable component is a portal service that may hold sensitive user and role data.
Impact
Successful exploitation lets an attacker execute arbitrary SQL commands against the backend database, enabling data theft or modification and potentially further compromise depending on database privileges.
Attack surface
The flaw is network-reachable via the User Manager HTTP endpoint (services/usermanager/users/) using the role or user parameter. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user is the likely entry point.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.52 (99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Apache Jetspeed to 2.3.1 or later, which the vendor advisory states fixes this issue.
- If immediate upgrade is not possible, restrict network access to the User Manager service and require strong authentication for all users.
- Apply input validation and parameterized queries or stored procedures to the role and user parameters as a compensating control.
- Review database account privileges used by Jetspeed and reduce them to the minimum needed.
- Monitor vendor and CVE feeds for any updated guidance on affected versions.
Detection
- Inspect web and application logs for requests to services/usermanager/users/ containing SQL metacharacters or unusual role/user parameter values.
- Enable database query logging and alert on anomalous SQL from the Jetspeed application account.
- Use a WAF or IDS rule set to flag SQL injection patterns targeting the User Manager endpoint.
- Baseline normal User Manager traffic and alert on deviations such as unexpected parameter lengths or encoding.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0710 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0710), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.