SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0050

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that…

HIGH 7.5EPSS 82.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 82.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
82.77% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
oracle/retail applications · apache/commons fileupload · apache/tomcat
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.