ZeroHour

CVE-2016-3092

CVSS 3.0
7.5 high
EPSS
36%p98
Published
()
Modified
Description

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Vendors
hpapachedebiancanonical
Products
icewall identity manager, icewall sso agent option, tomcat, debian linux, commons fileupload, ubuntu linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.