Vulnerability record · CVE-2016-0784 · published 11 April 2016
CVE-2016-0784: Apache OpenMeetings backup import path traversal allows arbitrary file write
Apache · Openmeetings
Apache OpenMeetings before 3.1.1 fails to sanitize ZIP archive entry names in the Import/Export System Backups feature, allowing directory traversal via '..' sequences. A remote authenticated administrator can write files to arbitrary paths on the server. The flaw matters because arbitrary file write on a Java web application can lead to code execution or configuration tampering.
Description
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityAlthough exploitation requires administrator privileges, the flaw allows arbitrary file write with a public exploit and a very high EPSS score, making it a serious risk for exposed OpenMeetings instances.
What it is
Apache OpenMeetings before 3.1.1 fails to sanitize ZIP archive entry names in the Import/Export System Backups feature, allowing directory traversal via '..' sequences. A remote authenticated administrator can write files to arbitrary paths on the server. The flaw matters because arbitrary file write on a Java web application can lead to code execution or configuration tampering.
Impact
An attacker with administrator privileges gains the ability to write arbitrary files anywhere the OpenMeetings process can write, which can be leveraged to plant web shells, alter configuration, or overwrite application code. The CVSS vector shows high integrity impact with no confidentiality or availability impact.
Attack surface
Reached remotely over the network through the backup import functionality; the attacker must be authenticated as an administrator and no user interaction is required. The CVSS vector is AV:N/AC:L/PR:L/UI:N, confirming network reachability with low privileges and no UI.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.56314 (99.006th percentile), indicating a high modeled likelihood of exploitation activity. Public references include an Exploit-DB entry and a Packet Storm advisory, so exploit code or technical detail is publicly available.
What to do
- Upgrade Apache OpenMeetings to 3.1.1 or later, which contains the vendor fix for the backup import path traversal.
- Restrict administrator accounts to trusted personnel and enforce strong authentication, since exploitation requires admin access.
- Disable or restrict the Import/Export System Backups feature if it is not needed in your deployment.
- Run OpenMeetings with a least-privilege service account and limit write permissions on the filesystem to reduce the impact of arbitrary file writes.
- Monitor and audit backup import activity and file system changes in OpenMeetings directories.
Detection
- Review OpenMeetings logs for backup import operations that reference ZIP entries containing '..' or absolute paths.
- Monitor file system writes in OpenMeetings web directories and configuration paths for unexpected new or modified files.
- Alert on administrator accounts performing backup imports outside of normal maintenance windows.
- Use file integrity monitoring on the OpenMeetings installation directory to detect unauthorized changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0784 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0784), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.