CVE-2016-3092
גבוהה 7.5
תיאור (מקור, אנגלית)
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CWE
- CWE-20
מוצרים מושפעים
hp: icewall identity manager; hp: icewall sso agent option; apache: tomcat; debian: debian linux; apache: commons fileupload; canonical: ubuntu linux
קישורים
- http://jvn.jp/en/jp/JVN89379547/index.html Vendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121 VDB EntryVendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743722 Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743738 Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743742 Vendor Advisory
- http://tomcat.apache.org/security-7.html Vendor Advisory
- http://tomcat.apache.org/security-8.html Vendor Advisory
- http://tomcat.apache.org/security-9.html Vendor Advisory
- http://jvn.jp/en/jp/JVN89379547/index.html Vendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121 VDB EntryVendor Advisory