The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
2013-10-28T21:55:05.157
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | jboss_enterprise_brms_platform | 5.3.1 | Yes |
Application | redhat | jboss_enterprise_portal_platform | 4.3.0 | Yes |
Application | redhat | jboss_enterprise_portal_platform | 5.2.2 | Yes |
Application | redhat | jboss_enterprise_portal_platform | 6.0.0 | Yes |
Application | redhat | jboss_enterprise_web_server | 1.0.2 | Yes |
Application | redhat | openshift | ≤ 3.1 | Yes |
Operating System | ubuntu | ubuntu | 10.04 | Yes |