CVE-2016-3092
Last modified
CVE-2016-3092 is a vulnerability of currently unknown severity. The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.. EPSS estimates a 35.93% chance of exploitation in the next 30 days.
Description
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Hp | Icewall Identity Manager | 5.0 | — |
| Hp | Icewall Sso Agent Option | 10.0 | — |
| Apache | Tomcat | 9.0.0 | Milestone1 |
| Apache | Tomcat | 8.0.0 | Rc1 |
| Apache | Tomcat | 8.0.1 | — |
| Apache | Tomcat | 8.0.3 | — |
| Apache | Tomcat | 8.0.5 | — |
| Apache | Tomcat | 8.0.8 | — |
| Apache | Tomcat | 8.0.11 | — |
| Apache | Tomcat | 8.0.12 | — |
| Apache | Tomcat | 8.0.14 | — |
| Apache | Tomcat | 8.0.15 | — |
| Apache | Tomcat | 8.0.17 | — |
| Apache | Tomcat | 8.0.18 | — |
| Apache | Tomcat | 8.0.20 | — |
| Apache | Tomcat | 8.0.21 | — |
| Apache | Tomcat | 8.0.22 | — |
| Apache | Tomcat | 8.0.23 | — |
| Apache | Tomcat | 8.0.24 | — |
| Apache | Tomcat | 8.0.26 | — |
| Apache | Tomcat | 8.0.27 | — |
| Apache | Tomcat | 8.0.28 | — |
| Apache | Tomcat | 8.0.29 | — |
| Apache | Tomcat | 8.0.30 | — |
| Apache | Tomcat | 8.0.32 | — |
| Apache | Tomcat | 8.0.33 | — |
| Apache | Tomcat | 8.0.35 | — |
| Debian | Debian Linux | 8.0 | — |
| Apache | Tomcat | 8.5.0 | — |
| Apache | Tomcat | 8.5.2 | — |
| Apache | Commons Fileupload | <= 1.3.1 | — |
| Canonical | Ubuntu Linux | 12.04 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 15.10 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Apache | Tomcat | 7.0.0 | — |
| Apache | Tomcat | 7.0.1 | — |
| Apache | Tomcat | 7.0.2 | — |
| Apache | Tomcat | 7.0.4 | — |
| Apache | Tomcat | 7.0.5 | — |
| Apache | Tomcat | 7.0.6 | — |
| Apache | Tomcat | 7.0.8 | — |
| Apache | Tomcat | 7.0.10 | — |
| Apache | Tomcat | 7.0.11 | — |
| Apache | Tomcat | 7.0.12 | — |
| Apache | Tomcat | 7.0.14 | — |
| Apache | Tomcat | 7.0.16 | — |
| Apache | Tomcat | 7.0.19 | — |
| Apache | Tomcat | 7.0.20 | — |
| Apache | Tomcat | 7.0.21 | — |
Showing 50 of 84 affected configurations. See NVD for the full list.
References
- http://jvn.jp/en/jp/JVN89379547/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121VDB Entry, Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743722Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743738Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743742Vendor Advisory
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://tomcat.apache.org/security-8.htmlVendor Advisory
- http://tomcat.apache.org/security-9.htmlVendor Advisory
- http://www.debian.org/security/2016/dsa-3609Third Party Advisory
- http://www.debian.org/security/2016/dsa-3611Third Party Advisory
- http://www.debian.org/security/2016/dsa-3614Third Party Advisory
- http://www.securityfocus.com/bid/91453Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3024-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3027-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1349468Issue Tracking
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05204371Patch, Permissions Required, Third Party Advisory
- http://jvn.jp/en/jp/JVN89379547/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121VDB Entry, Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743722Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743738Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1743742Vendor Advisory
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://tomcat.apache.org/security-8.htmlVendor Advisory
- http://tomcat.apache.org/security-9.htmlVendor Advisory
- http://www.debian.org/security/2016/dsa-3609Third Party Advisory
- http://www.debian.org/security/2016/dsa-3611Third Party Advisory
- http://www.debian.org/security/2016/dsa-3614Third Party Advisory
- http://www.securityfocus.com/bid/91453Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3024-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-3027-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1349468Issue Tracking
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05204371Patch, Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-3092?
How severe is CVE-2016-3092?
How do I fix CVE-2016-3092?
Are you affected by CVE-2016-3092?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
