CVE-2013-2186

Scores

EPSS

0.871high87.1%
0%20%40%60%80%100%

Percentile: 87.1%

CVSS

7.5high2.0
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhat

CWEs

CWE-20CWE-626

Related Vulnerabilities

Exploits

Recommendations

Source: nvd

The References section of this erratum contains a download link (you mustlog in to download the update). Before applying the update, back up yourexisting Red Hat JBoss Enterprise Web Server installation (including allapplications and configuration files).
The JBoss server process must be restarted for the update to take effect.

URL: http://rhn.redhat.com/errata/RHSA-2013-1429.html

Source: nvd

Before applying this update, make sure all previously released erratarelevant to your system have been applied.
This update is available via the Red Hat Network. Details on how touse the Red Hat Network to apply this update are available athttps://access.redhat.com/site/articles/11258

URL: http://rhn.redhat.com/errata/RHSA-2013-1428.html

Vulnerable Software (126)

Type: Configuration

Product: atomic-openshift

Operating System: rhel

Trait:
{  "fixed": "3.1.1.6-1.git.0.b57e8bd.el7aos"}

Source: redhat

Type: Configuration

Product: heapster

Operating System: rhel

Trait:
{  "fixed": "0.18.2-3.gitaf4752e.el7aos"}

Source: redhat

Type: Configuration

Product: jakarta-commons-fileupload

Operating System: rhel

Trait:
{  "fixed": "1.1.1-7.7.ep5.el5"}

Source: redhat

Type: Configuration

Product: jakarta-commons-fileupload

Operating System: rhel

Trait:
{  "fixed": "1.1.1-7.7.ep5.el6"}

Source: redhat

Type: Configuration

Product: jenkins

Operating System: debian

Trait:
{  "fixed": "1.565.3-1"}

Source: debian

Type: Configuration

Product: jenkins

Operating System: rhel

Trait:
{  "fixed": "1.625.3-2.el7aos"}

Source: redhat

Type: Configuration

Product: libcommons-fileupload-java

Operating System: debian

Trait:
{  "fixed": "1.3-2.1"}

Source: debian

Type: Configuration

Product: nodejs-align-text

Operating System: rhel

Trait:
{  "fixed": "0.1.3-2.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-ansi-green

Operating System: rhel

Trait:
{  "fixed": "0.1.1-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-ansi-wrap

Operating System: rhel

Trait:
{  "fixed": "0.1.0-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-anymatch

Operating System: rhel

Trait:
{  "fixed": "1.3.0-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-arr-diff

Operating System: rhel

Trait:
{  "fixed": "2.0.0-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-arr-flatten

Operating System: rhel

Trait:
{  "fixed": "1.0.1-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-array-unique

Operating System: rhel

Trait:
{  "fixed": "0.2.1-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-arrify

Operating System: rhel

Trait:
{  "fixed": "1.0.0-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-async-each

Operating System: rhel

Trait:
{  "fixed": "1.0.0-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-binary-extensions

Operating System: rhel

Trait:
{  "fixed": "1.3.1-1.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-braces

Operating System: rhel

Trait:
{  "fixed": "1.8.2-2.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-capture-stack-trace

Operating System: rhel

Trait:
{  "fixed": "1.0.0-2.el7aos"}

Source: redhat

Type: Configuration

Product: nodejs-chokidar

Operating System: rhel

Trait:
{  "fixed": "1.4.1-2.el7aos"}

Source: redhat