UNIX symbolic link following in Apache Commons FileUpload - CVE-2013-0248

 

UNIX symbolic link following in Apache Commons FileUpload - CVE-2013-0248

Published: July 19, 2021


Vulnerability identifier: #VU54943
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0248
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue. The application uses the /tmp directory for uploaded files. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Affected software

Apache Commons FileUpload
Gentoo Linux
IBM App Connect for Healthcare
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Integration Designer

How to mitigate CVE-2013-0248

Install updates from vendor's website.

Apache Commons FileUpload - update to 1.3
IBM Tivoli Business Service Manager - update to 6.2.0.3
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.2.0.2

External References

Related Security Bulletins