CVE-2013-2186
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
- Affected products
- Apache Commons Fileupload, Oracle Weblogic Server, Red Hat Jboss Brms, Red Hat Jboss Portal, Red Hat Jboss Web Server, Suse
- Redhat Jboss Enterprise Brms Platform
- = 5.3.1
- Redhat Jboss Enterprise Portal Platform
- = 4.3.0, 5.2.2, 6.0.0
- Redhat Jboss Enterprise Web Server
- = 1.0.2
- Redhat Openshift
- ≤ 3.1
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 12.8% (96th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2013-10-28
CVE-2013-2186 at NVD
No indexed exploits for CVE-2013-2186 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-2186 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.