vendor:
Commons FileUpload and Apache Tomcat
by:
Oren Hafif, Trustwave SpiderLabs Research
7,5
CVSS
HIGH
Denial-of-Service
400
CWE
Product Name: Commons FileUpload and Apache Tomcat
Affected Version From: Apache Commons FileUpload 1.3.1 and earlier
Affected Version To: Apache Tomcat 6.0.37 and earlier
Patch Exists: YES
Related CWE: CVE-2014-0050
CPE: a:apache:commons_fileupload:1.3.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/struts-cve-2014-0050/, https://www.rapid7.com/db/vulnerabilities/ibm-was-cve-2014-0050/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-alas-2014-312/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2014-0050/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-0050/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-0050/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2014-0050/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2014-0050/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-0253/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-0429/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-0526/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-0525/, https://www.rapid7.com/db/vulnerabilities/apache-tomcat-cve-2014-0050/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
CVE-2014-0050 Apache Commons FileUpload and Apache Tomcat Denial-of-Service
This is a Proof of Concept code that was created for the sole purpose of assisting system administrators in evaluating whether their applications are vulnerable to this issue or not. The code sends a number of requests to the server with a specially crafted multipart/form-data request, which can cause the server to become unresponsive.
Mitigation:
System administrators should ensure that their applications are not vulnerable to this issue by applying the appropriate patches.