← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-2186

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:12.67%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
redhat jboss_enterprise_brms_platform 5.3.1
redhat jboss_enterprise_portal_platform 4.3.0, 5.2.2, 6.0.0
redhat jboss_enterprise_web_server 1.0.2
redhat openshift all
ubuntu ubuntu 10.04

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
12.666%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2013-02-19T00:00:00
Published2013-10-28T21:00:00
Patch Date2013-10-15
Last Updated2024-08-06T15:27:40

LINK COPIED TO CLIPBOARD