VDB

DEBIAN-CVE-2016-3092

DEBIAN-CVE-2016-3092 PUBLISHED CVSS 7.5 HIGH

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:12libcommons-fileupload-java0, 0, 0
Debian:11libcommons-fileupload-java0, 0, 0
Debian:13libcommons-fileupload-java0, 0, 0
Debian:14libcommons-fileupload-java0, 0, 0

Timeline

  • Jul 4, 2016 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›