← All CVEs

CVE-2013-2186

high · 7.5

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.

7.5
CVSS
12.4%
EPSS (exploit prob.)
96th
EPSS percentile
2013-10-28
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
redhatjboss_enterprise_brms_platform5.3.1
redhatjboss_enterprise_portal_platform4.3.0
redhatjboss_enterprise_portal_platform5.2.2
redhatjboss_enterprise_portal_platform6.0.0
redhatjboss_enterprise_web_server1.0.2
redhatopenshift<= 3.1
ubuntuubuntu10.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-2186