Описание
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat JBoss BRMS 5 | commons-fileupload | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | commons-fileupload | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | dsp-5.3 | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | eap-4.x | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | eap-5 | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | eds-5 | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | ewp-5 | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | fuse-6 | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | jbds | Will not fix | ||
Red Hat JBoss Operations Network 3.1 | commons-fileupload | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS2
Связанные уязвимости
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
The DiskFileItem class in Apache Commons FileUpload, as used in Red Ha ...
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
7.5 High
CVSS2