VDB
CVE-2013-2186
CVE-2013-2186
PUBLISHED
Reported by redhat · Published October 28, 2013
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
| Maven | commons-fileupload:commons-fileupload | 1-alpha0, 1-alpha0 |
Timeline
- Oct 28, 2013 CVE Published
- Jan 8, 2018 CVE Updated
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 17, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 24, 2023 EPSS Score
- Jul 15, 2023 EPSS Score
- Sep 6, 2023 EPSS Score
References
- RHSA-2013:1430 vendor-advisoryx_refsource_REDHAT
- RHSA-2013:1429 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- apache-commons-cve20132186-file-overrwite(88133) vdb-entryx_refsource_XF
- openSUSE-SU-2013:1571 vendor-advisoryx_refsource_SUSE
- x_refsource_CONFIRM
- 55716 third-party-advisoryx_refsource_SECUNIA
- x_refsource_CONFIRM
- openSUSE-SU-2013:1596 vendor-advisoryx_refsource_SUSE
- SUSE-SU-2013:1660 vendor-advisoryx_refsource_SUSE
- RHSA-2013:1428 vendor-advisoryx_refsource_REDHAT
- DSA-2827 vendor-advisoryx_refsource_DEBIAN
- RHSA-2016:0070 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- RHSA-2013:1442 vendor-advisoryx_refsource_REDHAT
- RHSA-2013:1448 vendor-advisoryx_refsource_REDHAT
- x_refsource_MISC
- 63174 vdb-entryx_refsource_BID
- USN-2029-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-2186 url
…and 1 more