CVE-2013-2186

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
redhatjboss_enterprise_brms_platform
5.3.1
redhatjboss_enterprise_portal_platform
4.3.0:cp07
redhatjboss_enterprise_portal_platform
5.2.2
redhatjboss_enterprise_portal_platform
6.0.0
redhatjboss_enterprise_web_server
1.0.2
redhatopenshift
𝑥
≤ 3.1
ubuntuubuntu
10.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libcommons-fileupload-java
bullseye
1.4-1
fixed
bookworm
1.4-2
fixed
sid
1.5-1
fixed
trixie
1.5-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcommons-fileupload-java
saucy
Fixed 1.3-2ubuntu0.1
released
raring
Fixed 1.2.2-1ubuntu0.13.04.1
released
quantal
Fixed 1.2.2-1ubuntu0.12.10.1
released
precise
Fixed 1.2.2-1ubuntu0.12.04.1
released
lucid
Fixed 1.2.1-3ubuntu2.1
released
References