Описание
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss BRMS 5 | commons-fileupload | Affected | ||
| Red Hat JBoss Operations Network 3 | commons-fileupload | Affected | ||
| Red Hat JBoss Portal 4 | commons-fileupload | Affected | ||
| Red Hat JBoss Portal 5 | commons-fileupload | Affected | ||
| Red Hat JBoss Portal 6 | commons-fileupload | Affected | ||
| Red Hat JBoss SOA Platform 4 | commons-fileupload | Affected | ||
| Red Hat JBoss SOA Platform 5 | commons-fileupload | Affected | ||
| JBoss Enterprise BRMS Platform 5.3 | Fixed | RHSA-2013:1430 | 15.10.2013 | |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | jakarta-commons-fileupload | Fixed | RHSA-2013:1428 | 15.10.2013 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 6 | jakarta-commons-fileupload | Fixed | RHSA-2013:1428 | 15.10.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS2
Связанные уязвимости
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
The DiskFileItem class in Apache Commons FileUpload, as used in Red Ha ...
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
7.5 High
CVSS2