Desereliazation of untrusted data in Apache Commons FileUpload - CVE-2016-1000031

 

Desereliazation of untrusted data in Apache Commons FileUpload - CVE-2016-1000031

Published: May 1, 2018 / Updated: July 19, 2021


Vulnerability identifier: #VU12312
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1000031
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to execute arbitrary code on the target system.

The weakness exists in DiskFileItem class of the FileUpload library due to deserialization of untrusted data. A remote attacker can execute arbitrary code under the context of the current process.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Apache Commons FileUpload
Apache Struts
Oracle Utilities Work and Asset Management
Oracle Communications Online Mediation Controller
Oracle Agile Engineering Data Management
Oracle Financial Services Analytical Applications Infrastructure
Oracle Insurance Rules Palette
MICROS Retail XBRi Loss Prevention
Oracle Business Intelligence Enterprise Edition
Oracle FLEXCUBE Universal Banking
Oracle Application Testing Suite
Oracle Retail Service Backbone
Oracle Retail Returns Management
Oracle Retail Central Office
Oracle Retail Back Office
Oracle Communications Convergence
Oracle Communications Services Gatekeeper
Oracle Communications Unified
Oracle Communications Contacts Server
Oracle Communications Application Session Controller
Oracle Communications Diameter Signaling Router (DSR)
Oracle Enterprise Data Quality
Enterprise Manager Base Platform
IBM Cloud Pak for Business Automation
IBM Cloud Application Performance Management (APM)
IBM App Connect for Healthcare
Oracle FLEXCUBE Core Banking
Tape Library ACSLS
Oracle Knowledge
Oracle Insurance Policy Administration
Oracle SOA Suite
Oracle Fusion Middleware MapViewer
Oracle WebCenter Sites
Oracle Insurance Calculation Engine
Oracle Virtual Directory
Oracle REST Data Services
Oracle FLEXCUBE Enterprise Limits and Collateral Management
Oracle Database Server
Opensuse
Oracle Retail Integration Bus
Siebel Apps - Marketing
IBM TRIRIGA

How to mitigate CVE-2016-1000031

Install update from vendor's website.

Apache Commons FileUpload - update to 1.3.3
Apache Struts - update to 2.3.36
Oracle Communications Services Gatekeeper - update to 6.1.0.4.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
IBM TRIRIGA - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins