9.8
CVSSv3

CVE-2016-1000031

Published: 25/10/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Commons FileUpload prior to 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache commons fileupload

Vendor Advisories

Apache Commons FileUpload before 133 DiskFileItem File Manipulation Remote Code Execution ...
On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 133 on systems using Struts 2336 or earlier releases Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the s ...

References

CWE-284http://www.securityfocus.com/bid/93604https://www.tenable.com/security/research/tra-2016-30http://www.zerodayinitiative.com/advisories/ZDI-16-570/https://issues.apache.org/jira/browse/FILEUPLOAD-279https://www.tenable.com/security/research/tra-2016-23https://www.tenable.com/security/research/tra-2016-12http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttps://issues.apache.org/jira/browse/WW-4812https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://security.netapp.com/advisory/ntap-20190212-0001/https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00036.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread.html/d66657323fd25e437face5e84899c8ca404ccd187e81c3f2fa8b6080%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://nvd.nist.govhttps://access.redhat.com/security/cve/cve-2016-1000031https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload