VDB
RHSA-2016%3A2071
RHSA-2016%3A2071
PUBLISHED
CVSS 7.5 HIGH
A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file if the boundary was the typical tens of bytes long.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 6.4 |
Timeline
- Oct 17, 2016 CVE Published
- Mar 4, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2016:2071 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/documentation/en/jboss-enterprise-application-platform/ advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=6.4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1349468 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_2071.json advisory
- https://access.redhat.com/security/cve/CVE-2016-3092 advisory
- https://www.cve.org/CVERecord?id=CVE-2016-3092 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-3092 advisory
- http://tomcat.apache.org/security-7.html advisory
- http://tomcat.apache.org/security-8.html advisory