Infinite loop in Apache Commons FileUpload - CVE-2014-0050
Published: January 23, 2017 / Updated: April 15, 2019
Vulnerability identifier: #VU5233
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0050
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS conditions on the target system.
The weakness exists due to boundary error when handling Content-Type HTTP header for multipart requests. By sending a specially crafted Content-Type header, containing 4092 characters in "boundary" field, a remote attacker can cause the application to enter into an infinite loop.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
Note: the vulnerability was being actively exploited.
The weakness exists due to boundary error when handling Content-Type HTTP header for multipart requests. By sending a specially crafted Content-Type header, containing 4092 characters in "boundary" field, a remote attacker can cause the application to enter into an infinite loop.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
Note: the vulnerability was being actively exploited.
Affected software
Apache Commons FileUpload
Apache Struts
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
FlashSystem V840 9846-AE1 & 9848-AE1
Integration Designer
Sterling Field Sales
IBM Sterling Order Management
Sterling Web Channel
Sterling Selling and Fulfillment Foundation
IBM App Connect for Healthcare
JBoss Enterprise Application Platform
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Storwize V3500
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
Apache Struts
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
FlashSystem V840 9846-AE1 & 9848-AE1
Integration Designer
Sterling Field Sales
IBM Sterling Order Management
Sterling Web Channel
Sterling Selling and Fulfillment Foundation
IBM App Connect for Healthcare
JBoss Enterprise Application Platform
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Storwize V3500
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
How to mitigate CVE-2014-0050
Update Apache Struts to version 2.3.16.1.
For Apache Commons FileUpload install version 1.3.1.
For Apache Commons FileUpload install version 1.3.1.
Apache Commons FileUpload - update to 1.3.1
Apache Struts - update to 2.3.16.1
Sterling Field Sales - addressed in versions SFS9.0-SFP3, SFS9.1.0- SFP3, SFS9.2.0- SFP3, SFS9.2.1- SFP3
IBM Tivoli Business Service Manager - update to 6.2.0.4
IBM Storwize V3500 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V7000 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V5000 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V3700 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Sterling Order Management - update to 8.5- SFP3
Sterling Web Channel - addressed in versions 9.0.0-FP6, 9.1.0-FP3
Sterling Selling and Fulfillment Foundation - addressed in versions 9.0.0- SFP3, 9.1.0- SFP3, 9.2.0- SFP3, 9.2.1-SFP3, 9.3.0- SFP2
IBM Security Verify Governance - update to 10.0.2.0.2
Apache Struts - update to 2.3.16.1
Sterling Field Sales - addressed in versions SFS9.0-SFP3, SFS9.1.0- SFP3, SFS9.2.0- SFP3, SFS9.2.1- SFP3
IBM Tivoli Business Service Manager - update to 6.2.0.4
IBM Storwize V3500 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V7000 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V5000 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V3700 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Sterling Order Management - update to 8.5- SFP3
Sterling Web Channel - addressed in versions 9.0.0-FP6, 9.1.0-FP3
Sterling Selling and Fulfillment Foundation - addressed in versions 9.0.0- SFP3, 9.1.0- SFP3, 9.2.0- SFP3, 9.2.1-SFP3, 9.3.0- SFP2
IBM Security Verify Governance - update to 10.0.2.0.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in Apache Struts
- Debian update for libcommons-fileupload-java
- SUSE Linux update for jakarta-commons-fileupload
- Amazon Linux AMI update for tomcat7
- Denial of service in Apache Commons FileUpload
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.2.1
- Gentoo update for Apache Commons FileUpload
- Multiple vulnerabilities in IBM FlashSystem 840 and V840
- Infinite loop in SAN Volume Controller and Storwize Family
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM App Connect for Healthcare
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Infinite loop in IBM Sterling Order Management, IBM Sterling Configure, Price, Quote and Sterling Web Channel
- Multiple vulnerabilities in IBM Tivoli Business Service Manager