← Vulnerability feed

Vulnerability record · CVE-2016-0784 · published 11 April 2016

CVE-2016-0784: Apache OpenMeetings backup import path traversal allows arbitrary file write

Apache · Openmeetings

Apache OpenMeetings before 3.1.1 fails to sanitize ZIP archive entry names in the Import/Export System Backups feature, allowing directory traversal via '..' sequences. A remote authenticated administrator can write files to arbitrary paths on the server. The flaw matters because arbitrary file write on a Java web application can lead to code execution or configuration tampering.

6.5 CVSS 3.0 Medium EPSS 56% · top 1.0% CWE-22 · Path traversal
6.5CVSS 3.0 base score, v2 4.0
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityAlthough exploitation requires administrator privileges, the flaw allows arbitrary file write with a public exploit and a very high EPSS score, making it a serious risk for exposed OpenMeetings instances.

What it is

Apache OpenMeetings before 3.1.1 fails to sanitize ZIP archive entry names in the Import/Export System Backups feature, allowing directory traversal via '..' sequences. A remote authenticated administrator can write files to arbitrary paths on the server. The flaw matters because arbitrary file write on a Java web application can lead to code execution or configuration tampering.

Impact

An attacker with administrator privileges gains the ability to write arbitrary files anywhere the OpenMeetings process can write, which can be leveraged to plant web shells, alter configuration, or overwrite application code. The CVSS vector shows high integrity impact with no confidentiality or availability impact.

Attack surface

Reached remotely over the network through the backup import functionality; the attacker must be authenticated as an administrator and no user interaction is required. The CVSS vector is AV:N/AC:L/PR:L/UI:N, confirming network reachability with low privileges and no UI.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.56314 (99.006th percentile), indicating a high modeled likelihood of exploitation activity. Public references include an Exploit-DB entry and a Packet Storm advisory, so exploit code or technical detail is publicly available.

What to do

  • Upgrade Apache OpenMeetings to 3.1.1 or later, which contains the vendor fix for the backup import path traversal.
  • Restrict administrator accounts to trusted personnel and enforce strong authentication, since exploitation requires admin access.
  • Disable or restrict the Import/Export System Backups feature if it is not needed in your deployment.
  • Run OpenMeetings with a least-privilege service account and limit write permissions on the filesystem to reduce the impact of arbitrary file writes.
  • Monitor and audit backup import activity and file system changes in OpenMeetings directories.

Detection

  • Review OpenMeetings logs for backup import operations that reference ZIP entries containing '..' or absolute paths.
  • Monitor file system writes in OpenMeetings web directories and configuration paths for unexpected new or modified files.
  • Alert on administrator accounts performing backup imports outside of normal maintenance windows.
  • Use file integrity monitoring on the OpenMeetings installation directory to detect unauthorized changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0784 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2017-7664Apache openmeetings xml external entity (xxe) vulnerabilityUploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.EPSS 2.3%9.8CVE-2024-54676Apache OpenMeetings OpenJPA deserialization of untrusted dataApache OpenMeetings versions from 2.1.0 before 8.0.0 ship default clustering instructions that omit OpenJPA serialization class white/black lists, al…EPSS 65%analysed9.8CVE-2023-28326Apache openmeetings missing authentication for critical function vulnerabilityVendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privile…EPSS 1.3%9.8CVE-2016-8736Apache openmeetings deserialization of untrusted data vulnerabilityApache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.EPSS 4.8%9.8CVE-2017-7673Apache openmeetings improper restriction of authentication attempts vulnerabilityApache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms …EPSS 1.6%8.8CVE-2017-7666Apache openmeetings cross-site scripting vulnerabilityApache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.EPSS 0.80%8.8CVE-2017-7681Apache openmeetings sql injection vulnerabilityApache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the …EPSS 1.3%8.2CVE-2017-7682Apache openmeetings vulnerabilityApache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2016-0784), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.