The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-528-1 | libcommons-fileupload-java security update |
![]() |
DLA-529-1 | tomcat7 security update |
![]() |
DSA-3609-1 | tomcat8 security update |
![]() |
DSA-3611-1 | libcommons-fileupload-java security update |
![]() |
DSA-3614-1 | tomcat7 security update |
![]() |
GHSA-fvm3-cfvj-gxqq | High severity vulnerability that affects commons-fileupload:commons-fileupload |
![]() |
USN-3024-1 | Tomcat vulnerabilities |
![]() |
USN-3027-1 | Tomcat vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T23:40:15.604Z
Reserved: 2016-03-10T00:00:00
Link: CVE-2016-3092

No data.

Status : Deferred
Published: 2016-07-04T22:59:04.303
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-3092


No data.