CVE-2016-3092

UnknownEPSS 35.93%

Last modified

CVE-2016-3092 is a vulnerability of currently unknown severity. The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.. EPSS estimates a 35.93% chance of exploitation in the next 30 days.

Description

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Metrics

EPSS Probability
35.93%

98.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
HpIcewall Identity Manager5.0
HpIcewall Sso Agent Option10.0
ApacheTomcat9.0.0Milestone1
ApacheTomcat8.0.0Rc1
ApacheTomcat8.0.1
ApacheTomcat8.0.3
ApacheTomcat8.0.5
ApacheTomcat8.0.8
ApacheTomcat8.0.11
ApacheTomcat8.0.12
ApacheTomcat8.0.14
ApacheTomcat8.0.15
ApacheTomcat8.0.17
ApacheTomcat8.0.18
ApacheTomcat8.0.20
ApacheTomcat8.0.21
ApacheTomcat8.0.22
ApacheTomcat8.0.23
ApacheTomcat8.0.24
ApacheTomcat8.0.26
ApacheTomcat8.0.27
ApacheTomcat8.0.28
ApacheTomcat8.0.29
ApacheTomcat8.0.30
ApacheTomcat8.0.32
ApacheTomcat8.0.33
ApacheTomcat8.0.35
DebianDebian Linux8.0
ApacheTomcat8.5.0
ApacheTomcat8.5.2
ApacheCommons Fileupload<= 1.3.1
CanonicalUbuntu Linux12.04
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux15.10
CanonicalUbuntu Linux16.04
ApacheTomcat7.0.0
ApacheTomcat7.0.1
ApacheTomcat7.0.2
ApacheTomcat7.0.4
ApacheTomcat7.0.5
ApacheTomcat7.0.6
ApacheTomcat7.0.8
ApacheTomcat7.0.10
ApacheTomcat7.0.11
ApacheTomcat7.0.12
ApacheTomcat7.0.14
ApacheTomcat7.0.16
ApacheTomcat7.0.19
ApacheTomcat7.0.20
ApacheTomcat7.0.21

Showing 50 of 84 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-3092?
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
How severe is CVE-2016-3092?
Severity scoring for CVE-2016-3092 is pending analysis. The EPSS model estimates a 35.93% probability of exploitation in the next 30 days.
How do I fix CVE-2016-3092?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-3092?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST