Resource exhaustion in Apache Commons FileUpload - CVE-2016-3092

 

Resource exhaustion in Apache Commons FileUpload - CVE-2016-3092

Published: July 22, 2016 / Updated: April 15, 2019


Vulnerability identifier: #VU197
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3092
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause denial of service conditions on the target system.

The vulnerability exists due to input validation error when processing very long boundary strings within the MultipartStream class in Apache Commons Fileupload. A remote user can cause denial of service conditions by sending specially crafted boundary string and consume excessive CPU resources.

Successful exploitation of this vulnerability may result in denial of service attack.


Affected software

Apache Commons FileUpload
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
Fedora
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
openSUSE Leap
FlashSystem 840 9840-AE1 & 9843-AE1
Integration Designer
Storage Copy Data Management
FlashSystem 900 9840-AE2 and 9843-AE2
IBM App Connect for Healthcare
JBoss Enterprise Application Platform
Oracle Knowledge
IBM Cloud Pak for Business Automation
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
jakarta-commons-fileupload-javadoc
jakarta-commons-fileupload
tomcat

How to mitigate CVE-2016-3092

Install updates from vendor's website.

Apache Commons FileUpload - update to 1.3.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
jakarta-commons-fileupload-javadoc - addressed in versions 1.1.1-122.8.1, 1.1.1-150000.4.8.1
jakarta-commons-fileupload - addressed in versions 1.1.1-122.8.1, 1.1.1-150000.4.8.1
Storage Copy Data Management - update to 2.2.26.0
IBM Tivoli Business Service Manager - update to 6.2.0.4
tomcat - addressed in versions 7.0.70-2.el6, 8.0.36-2.fc23, 8.0.36-2.fc24, 8.0.36-2.fc25
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.2.0.2

External References

Related Security Bulletins