Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Freebsd | — | Upgrade axis2Upgrade payara | Aug 9, 2017 | Aug 9, 2017 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Apr 27, 2018 | Oct 25, 2016 |
| Oracle Missing Cpu Jul 2020 | — | Apply the July 2020 Critical Patch Update (CPU) for Oracle Database | Jul 14, 2020 | Oct 25, 2016 |
| Struts | — | Upgrade to Apache Struts version 2.5.12Update Struts projects to use the latest released version of Commons FileUpload library | Nov 7, 2018 | Nov 5, 2018 |
| Suse | — | Upgrade jakarta-commons-fileupload-javadocUpgrade jakarta-commons-fileupload | May 11, 2019 | Oct 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub