Vulnerability Description
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Brms Platform | 5.3.1 |
| Redhat | Jboss Enterprise Portal Platform | 4.3.0 |
| Redhat | Jboss Enterprise Web Server | 1.0.2 |
| Redhat | Openshift | <= 3.1 |
| Ubuntu | Ubuntu | 10.04 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00033.html
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00050.html
- http://rhn.redhat.com/errata/RHSA-2013-1428.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1429.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1430.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1442.html
- http://rhn.redhat.com/errata/RHSA-2013-1448.htmlVendor Advisory
- http://secunia.com/advisories/55716
- http://ubuntu.com/usn/usn-2029-1
- http://www.debian.org/security/2013/dsa-2827
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.securityfocus.com/bid/63174
FAQ
What is CVE-2013-2186?
CVE-2013-2186 is a vulnerability with a CVSS score of 7.5 (HIGH). The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write t...
How severe is CVE-2013-2186?
CVE-2013-2186 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2186?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Jboss Enterprise Brms Platform, Redhat Jboss Enterprise Portal Platform, Redhat Jboss Enterprise Web Server, Redhat Openshift, Ubuntu Ubuntu.