Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-3092


The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.


Published

2016-07-04T22:59:04.303

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hp icewall_identity_manager 5.0 Yes
Application hp icewall_sso_agent_option 10.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 8.0.0 Yes
Application apache tomcat 8.0.0 Yes
Application apache tomcat 8.0.0 Yes
Application apache tomcat 8.0.0 Yes
Application apache tomcat 8.0.1 Yes
Application apache tomcat 8.0.3 Yes
Application apache tomcat 8.0.5 Yes
Application apache tomcat 8.0.8 Yes
Application apache tomcat 8.0.11 Yes
Application apache tomcat 8.0.12 Yes
Application apache tomcat 8.0.14 Yes
Application apache tomcat 8.0.15 Yes
Application apache tomcat 8.0.17 Yes
Application apache tomcat 8.0.18 Yes
Application apache tomcat 8.0.20 Yes
Application apache tomcat 8.0.21 Yes
Application apache tomcat 8.0.22 Yes
Application apache tomcat 8.0.23 Yes
Application apache tomcat 8.0.24 Yes
Application apache tomcat 8.0.26 Yes
Application apache tomcat 8.0.27 Yes
Application apache tomcat 8.0.28 Yes
Application apache tomcat 8.0.29 Yes
Application apache tomcat 8.0.30 Yes
Application apache tomcat 8.0.32 Yes
Application apache tomcat 8.0.33 Yes
Application apache tomcat 8.0.35 Yes
Operating System debian debian_linux 8.0 Yes
Application apache tomcat 8.5.0 Yes
Application apache tomcat 8.5.2 Yes
Application apache commons_fileupload ≤ 1.3.1 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System canonical ubuntu_linux 14.04 Yes
Operating System canonical ubuntu_linux 15.10 Yes
Operating System canonical ubuntu_linux 16.04 Yes
Application apache tomcat 7.0.0 Yes
Application apache tomcat 7.0.0 Yes
Application apache tomcat 7.0.1 Yes
Application apache tomcat 7.0.2 Yes
Application apache tomcat 7.0.2 Yes
Application apache tomcat 7.0.4 Yes
Application apache tomcat 7.0.4 Yes
Application apache tomcat 7.0.5 Yes
Application apache tomcat 7.0.5 Yes
Application apache tomcat 7.0.6 Yes
Application apache tomcat 7.0.8 Yes
Application apache tomcat 7.0.10 Yes
Application apache tomcat 7.0.11 Yes
Application apache tomcat 7.0.12 Yes
Application apache tomcat 7.0.14 Yes
Application apache tomcat 7.0.16 Yes
Application apache tomcat 7.0.19 Yes
Application apache tomcat 7.0.20 Yes
Application apache tomcat 7.0.21 Yes
Application apache tomcat 7.0.22 Yes
Application apache tomcat 7.0.23 Yes
Application apache tomcat 7.0.25 Yes
Application apache tomcat 7.0.26 Yes
Application apache tomcat 7.0.27 Yes
Application apache tomcat 7.0.28 Yes
Application apache tomcat 7.0.29 Yes
Application apache tomcat 7.0.30 Yes
Application apache tomcat 7.0.32 Yes
Application apache tomcat 7.0.33 Yes
Application apache tomcat 7.0.34 Yes
Application apache tomcat 7.0.35 Yes
Application apache tomcat 7.0.37 Yes
Application apache tomcat 7.0.39 Yes
Application apache tomcat 7.0.40 Yes
Application apache tomcat 7.0.41 Yes
Application apache tomcat 7.0.42 Yes
Application apache tomcat 7.0.47 Yes
Application apache tomcat 7.0.50 Yes
Application apache tomcat 7.0.52 Yes
Application apache tomcat 7.0.53 Yes
Application apache tomcat 7.0.54 Yes
Application apache tomcat 7.0.55 Yes
Application apache tomcat 7.0.56 Yes
Application apache tomcat 7.0.57 Yes
Application apache tomcat 7.0.59 Yes
Application apache tomcat 7.0.61 Yes
Application apache tomcat 7.0.62 Yes
Application apache tomcat 7.0.63 Yes
Application apache tomcat 7.0.64 Yes
Application apache tomcat 7.0.65 Yes
Application apache tomcat 7.0.67 Yes
Application apache tomcat 7.0.68 Yes
Application apache tomcat 7.0.69 Yes

References