SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-2186

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a…

HIGH 7.5EPSS 12.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 12.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
12.43% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
redhat/jboss enterprise brms platform · redhat/jboss enterprise portal platform · redhat/jboss enterprise web server · redhat/openshift · ubuntu/ubuntu
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.