Resource exhaustion in Apache Commons FileUpload - CVE-2016-3092
Published: July 22, 2016 / Updated: April 15, 2019
Vulnerability identifier: #VU197
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3092
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause denial of service conditions on the target system.
The vulnerability exists due to input validation error when processing very long boundary strings within the MultipartStream class in Apache Commons Fileupload. A remote user can cause denial of service conditions by sending specially crafted boundary string and consume excessive CPU resources.
Successful exploitation of this vulnerability may result in denial of service attack.
The vulnerability exists due to input validation error when processing very long boundary strings within the MultipartStream class in Apache Commons Fileupload. A remote user can cause denial of service conditions by sending specially crafted boundary string and consume excessive CPU resources.
Successful exploitation of this vulnerability may result in denial of service attack.
Affected software
Apache Commons FileUpload
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
Fedora
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
openSUSE Leap
FlashSystem 840 9840-AE1 & 9843-AE1
Integration Designer
Storage Copy Data Management
FlashSystem 900 9840-AE2 and 9843-AE2
IBM App Connect for Healthcare
JBoss Enterprise Application Platform
Oracle Knowledge
IBM Cloud Pak for Business Automation
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
jakarta-commons-fileupload-javadoc
jakarta-commons-fileupload
tomcat
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
Fedora
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
openSUSE Leap
FlashSystem 840 9840-AE1 & 9843-AE1
Integration Designer
Storage Copy Data Management
FlashSystem 900 9840-AE2 and 9843-AE2
IBM App Connect for Healthcare
JBoss Enterprise Application Platform
Oracle Knowledge
IBM Cloud Pak for Business Automation
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
jakarta-commons-fileupload-javadoc
jakarta-commons-fileupload
tomcat
How to mitigate CVE-2016-3092
Install updates from vendor's website.
Apache Commons FileUpload - update to 1.3.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
jakarta-commons-fileupload-javadoc - addressed in versions 1.1.1-122.8.1, 1.1.1-150000.4.8.1
jakarta-commons-fileupload - addressed in versions 1.1.1-122.8.1, 1.1.1-150000.4.8.1
Storage Copy Data Management - update to 2.2.26.0
IBM Tivoli Business Service Manager - update to 6.2.0.4
tomcat - addressed in versions 7.0.70-2.el6, 8.0.36-2.fc23, 8.0.36-2.fc24, 8.0.36-2.fc25
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.2.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
jakarta-commons-fileupload-javadoc - addressed in versions 1.1.1-122.8.1, 1.1.1-150000.4.8.1
jakarta-commons-fileupload - addressed in versions 1.1.1-122.8.1, 1.1.1-150000.4.8.1
Storage Copy Data Management - update to 2.2.26.0
IBM Tivoli Business Service Manager - update to 6.2.0.4
tomcat - addressed in versions 7.0.70-2.el6, 8.0.36-2.fc23, 8.0.36-2.fc24, 8.0.36-2.fc25
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.2.0.2
External References
Related Security Bulletins
- Ubuntu update for Tomcat
- Debian update for tomcat7
- Debian update for libcommons-fileupload-java
- Multiple vulnerabilities in Oracle GlassFish Server
- Amazon Linux AMI update for tomcat7, tomcat8
- Denial of service in Apache Commons FileUpload
- Red Hat update for jboss-ec2-eap
- Multiple vulnerabilities in Oracle Knowledge
- Gentoo update for Apache Commons FileUpload
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- SUSE update for jakarta-commons-fileupload
- SUSE update for jakarta-commons-fileupload
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM App Connect for Healthcare
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Fedora EPEL 6 update for tomcat
- Fedora 23 update for tomcat
- Fedora 24 update for tomcat
- Fedora 25 update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation