The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
http://www.zerodayinitiative.com/advisories/ZDI-16-357
http://www.zerodayinitiative.com/advisories/ZDI-16-356
http://rhn.redhat.com/errata/RHSA-2016-2036.html
http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt