Input validation error in Apache Commons FileUpload - CVE-2013-2186

 

Input validation error in Apache Commons FileUpload - CVE-2013-2186

Published: September 25, 2023


Vulnerability identifier: #VU81098
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2186
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files on the system.

The vulnerability exists due to insufficient validation of user-supplied input when processing file names with a NULL byte within the DiskFileItem class. A remote attacker can upload a specially crafted file with a NULL byte in its name and overwrite arbitrary files on the system.


Affected software

Apache Commons FileUpload
IBM App Connect for Healthcare
Integration Designer
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance

How to mitigate CVE-2013-2186

Install updates from vendor's website.

Apache Commons FileUpload - update to 1.2.2
IBM Tivoli Business Service Manager - update to 6.2.0.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.2.0.2

External References

Related Security Bulletins