cbcvebase.
CVE-2016-1000031
published 2016-10-25

CVE-2016-1000031: Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
34.73%
98.2th percentile
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Affected

2 ranges
VendorProductVersion rangeFixed in
apachecommons_fileupload<= 1.3.2
debianlibcommons-fileupload-java

Detection & IOCsextracted from sources · hover to see the quote

pathWEB-INF/lib
  • Target systems running Apache Struts 2.3.36 or prior are vulnerable; the attack vector is HTTP and the exploit is remotely triggered via crafted file upload data submitted to the application.
  • The vulnerability is exploited by submitting crafted (malicious) data to the file upload endpoint of an affected system; inspect multipart/file-upload HTTP requests for anomalous or serialized payloads targeting DiskFileItem deserialization.
  • Scan for presence of commons-fileupload JAR versions older than 1.3.3 in WEB-INF/lib directories of deployed Java web applications, particularly those built on Apache Struts 2.
  • Protocol used for exploitation is HTTP; the vulnerability is remotely exploitable with no authentication required (CVSS 9.8).
  • ·The Commons FileUpload library can be patched independently of the full Struts upgrade by replacing only the JAR file, which may result in partially patched deployments that are still detectable by version scanning.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.