CVE-2013-2185
Last modified
CVE-2013-2185 is a vulnerability of currently unknown severity. The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. EPSS estimates a 7.20% chance of exploitation in the next 30 days.
Description
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | <= 7.0.39 |
| Redhat | Jboss Enterprise Application Platform | 6.1.0 |
| Redhat | Jboss Enterprise Portal Platform | 6.0.0 |
References
- http://rhn.redhat.com/errata/RHSA-2013-1193.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1194.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1265.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1193.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1194.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1265.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2185?
How severe is CVE-2013-2185?
How do I fix CVE-2013-2185?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2179X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when …
- CVE-2013-2180Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2013-2181Cross-site scripting (XSS) vulnerability in the Directory Li…
- CVE-2013-2182The Mandril security plugin in Monkey HTTP Daemon (monkeyd) …
- CVE-2013-2183Monkey HTTP Daemon has local security bypass7.1
- CVE-2013-2184Movable Type before 5.2.6 does not properly use the Storable…
- CVE-2013-2186The DiskFileItem class in Apache Commons FileUpload, as used…
- CVE-2013-2187Cross-site scripting (XSS) vulnerability in Apache Archiva 1…
- CVE-2013-2188A certain Red Hat patch to the do_filp_open function in fs/n…
- CVE-2013-2189Apache OpenOffice.org (OOo) before 4.0 allows remote attacke…
- CVE-2013-2190The translate_hierarchy_event function in x11/clutter-device…
- CVE-2013-2191python-bugzilla before 0.9.0 does not validate X.509 certifi…
Are you affected by CVE-2013-2185?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
