CVE-2016-1000031
published 2016-10-25CVE-2016-1000031: Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
34.73%
98.2th percentile
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_fileupload | <= 1.3.2 | — |
| debian | libcommons-fileupload-java | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target systems running Apache Struts 2.3.36 or prior are vulnerable; the attack vector is HTTP and the exploit is remotely triggered via crafted file upload data submitted to the application. ↗
- →The vulnerability is exploited by submitting crafted (malicious) data to the file upload endpoint of an affected system; inspect multipart/file-upload HTTP requests for anomalous or serialized payloads targeting DiskFileItem deserialization. ↗
- →Scan for presence of commons-fileupload JAR versions older than 1.3.3 in WEB-INF/lib directories of deployed Java web applications, particularly those built on Apache Struts 2. ↗
- →Protocol used for exploitation is HTTP; the vulnerability is remotely exploitable with no authentication required (CVSS 9.8). ↗
- ·The Commons FileUpload library can be patched independently of the full Struts upgrade by replacing only the JAR file, which may result in partially patched deployments that are still detectable by version scanning. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Access Control in commons-fileupload
osv·2018-12-21
CVE-2016-1000031 [CRITICAL] Improper Access Control in commons-fileupload
Improper Access Control in commons-fileupload
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
GHSA
Improper Access Control in commons-fileupload
ghsa·2018-12-21
CVE-2016-1000031 [CRITICAL] CWE-284 Improper Access Control in commons-fileupload
Improper Access Control in commons-fileupload
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
OSV
CVE-2016-1000031: Apache Commons FileUpload before 1
osv·2016-10-25·CVSS 9.8
CVE-2016-1000031 [CRITICAL] CVE-2016-1000031: Apache Commons FileUpload before 1
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Development tools (Apache Commons FileUpload) — CVE-2016-1000031
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2016-1000031 [CRITICAL] Oracle Oracle Insurance Applications Risk Matrix: Development tools (Apache Commons FileUpload) — CVE-2016-1000031
Oracle Oracle Insurance Applications Risk Matrix: Development tools (Apache Commons FileUpload) vulnerability
CVE: CVE-2016-1000031
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Commons FileUpload) — CVE-2016-1000031
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2016-1000031 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Commons FileUpload) — CVE-2016-1000031
Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Commons FileUpload) vulnerability
CVE: CVE-2016-1000031
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle REST Data Services Risk Matrix: General (Apache Commons FileUpload) — CVE-2016-1000031
vendor_oracle·2020-10-15·CVSS 8.0
CVE-2016-1000031 [CRITICAL] Oracle Oracle REST Data Services Risk Matrix: General (Apache Commons FileUpload) — CVE-2016-1000031
Oracle Oracle REST Data Services Risk Matrix: General (Apache Commons FileUpload) vulnerability
CVE: CVE-2016-1000031
CVSS: 8.0
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Database Server Risk Matrix: MapViewer (Apache Commons FileUpload) — CVE-2016-1000031
vendor_oracle·2020-07-15·CVSS 8.8
CVE-2016-1000031 [CRITICAL] Oracle Oracle Database Server Risk Matrix: MapViewer (Apache Commons FileUpload) — CVE-2016-1000031
Oracle Oracle Database Server Risk Matrix: MapViewer (Apache Commons FileUpload) vulnerability
CVE: CVE-2016-1000031
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Commons FileUpload) — CVE-2016-1000031
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2016-1000031 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Commons FileUpload) — CVE-2016-1000031
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Commons FileUpload) vulnerability
CVE: CVE-2016-1000031
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Systems Risk Matrix: Software (Apache Commons FileUpload) — CVE-2016-1000031
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2016-1000031 [CRITICAL] Oracle Oracle Systems Risk Matrix: Software (Apache Commons FileUpload) — CVE-2016-1000031
Oracle Oracle Systems Risk Matrix: Software (Apache Commons FileUpload) vulnerability
CVE: CVE-2016-1000031
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Cisco
Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
vendor_cisco·2018-11-07·CVSS 9.8
CVE-2016-1000031 [CRITICAL] CWE-502 Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031.
The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to an affected system
Red Hat
FileUpload: DiskFileItem file manipulation
vendor_redhat·2016-04-20·CVSS 9.8
CVE-2016-1000031 [CRITICAL] CWE-502 FileUpload: DiskFileItem file manipulation
FileUpload: DiskFileItem file manipulation
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Package: commons-fileupload (Red Hat AMQ Broker 7) - Not affected
Package: tomcat (Red Hat Enterprise Linux 7) - Not affected
Package: commons-fileupload (Red Hat JBoss A-MQ 6) - Not affected
Package: commons-fileupload (Red Hat JBoss BRMS 6) - Not affected
Package: commons-fileupload (Red Hat JBoss Data Virtualization 6) - Not affected
Package: jbossas (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: commons-fileupload (Red Hat JBoss Fuse 6) - Not affected
Package: commons-fileupload (Red Hat JBoss Fuse Service Works 6) - Not affected
Package: commons-fileupload (Red Hat JBoss Operations Network 3) - Not affected
Package
Debian
CVE-2016-1000031: libcommons-fileupload-java - Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Cod...
vendor_debian·2016·CVSS 9.8
CVE-2016-1000031 [CRITICAL] CVE-2016-1000031: libcommons-fileupload-java - Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Cod...
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Cisco
Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
vendor_cisco
CVE-2016-1000031 Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
CVE-2016-1000031: Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to a
No detection rules found.
No public exploits indexed.
Tenable
Oracle January 2020 Critical Patch Update Contains 255 CVEs
blogs_tenable·2020-01-15
Oracle January 2020 Critical Patch Update Contains 255 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle Critical Patch Update for October Contains 180 Fixes
blogs_tenable·2019-10-16
Oracle Critical Patch Update for October Contains 180 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle Critical Patch Update For April Contains 297 Fixes
blogs_tenable·2019-04-17
Oracle Critical Patch Update For April Contains 297 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15·CVSS 9.8
[CRITICAL] Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Blog / Cyber Exposure Alerts
Subscribe
# Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Satnam Narang
January 15, 2019
2 Min Read
Oracle addresses nearly 300 vulnerabilities in the first Critical Patch Update of 2019.
## Background
On January 15, Oracle released its Critical Patch Update, a quarterly publication of fixes for vulnerabilities. This month’s update contains nearly 300 fixes across a number of Oracle products.
## Analysis
The Critical Patch Update for January 2019 addresses a variety of vulnerabilities. For instance, Oracle published 30 fixes for MySQL, including a fix for MySQL Workbench to address the libssh vulnerability (CVE-2018-10933). There are also several fixes for CVE-2017-5645, a deserialization vulnerability in Apache Log4j, as well as CV
Tenable
Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
blogs_tenable·2018-11-05·CVSS 9.8
CVE-2016-1000031 [CRITICAL] Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
Blog / Cyber Exposure Alerts
Subscribe
# Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
Satnam Narang
November 5, 2018
2 Min Read
Apache Software Foundation announces a security update for Apache Struts to address a vulnerability in the Commons FileUpload library that could lead to remote code execution. We recommend updating now.
## Background
On November 5, the Apache Software Foundation (ASF) published a security announcement to Apache Struts project administrators about CVE-2016-1000031, a vulnerability in the Commons FileUpload library originally reported by Tenable’s Research team in 2016. This library ships as part of Apache Struts 2 and is used as the default mechanism for file uploads. The ASF reports that Apache Struts 2.
Tenable
Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
blogs_tenable·2018-11-05·CVSS 9.8
[CRITICAL] Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
NoiseLetter February 2026
blogs_greynoiseio
NoiseLetter February 2026
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bugzilla
CVE-2016-1000031 Apache Commons FileUpload: DiskFileItem file manipulation
bugzilla·2016-11-09·CVSS 9.8
CVE-2016-1000031 [CRITICAL] CVE-2016-1000031 Apache Commons FileUpload: DiskFileItem file manipulation
CVE-2016-1000031 Apache Commons FileUpload: DiskFileItem file manipulation
There exists a Java Object in the Apache Commons FileUpload library that can be manipulated in such a way that when it is deserialized, it can write or copy files to disk in arbitrary locations. Furthermore, while the Object can be used alone, this new vector can be integrated with ysoserial to upload and execute binaries in a single deserialization call. This may or may not work depending on an application's implementation of the FileUpload library.
External References:
http://www.tenable.com/security/research/tra-2016-12
Discussion:
We agree with Apache's assessment that this does not represent a valid vulnerability in the Commons File Upload library. We have previously written about Java deserialization flaw
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00036.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/93604http://www.zerodayinitiative.com/advisories/ZDI-16-570/https://issues.apache.org/jira/browse/FILEUPLOAD-279https://issues.apache.org/jira/browse/WW-4812https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/d66657323fd25e437face5e84899c8ca404ccd187e81c3f2fa8b6080%40%3Cannounce.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190212-0001/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.tenable.com/security/research/tra-2016-12https://www.tenable.com/security/research/tra-2016-23https://www.tenable.com/security/research/tra-2016-30http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00036.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/93604http://www.zerodayinitiative.com/advisories/ZDI-16-570/https://issues.apache.org/jira/browse/FILEUPLOAD-279https://issues.apache.org/jira/browse/WW-4812https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/d66657323fd25e437face5e84899c8ca404ccd187e81c3f2fa8b6080%40%3Cannounce.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190212-0001/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.tenable.com/security/research/tra-2016-12https://www.tenable.com/security/research/tra-2016-23https://www.tenable.com/security/research/tra-2016-30
2016-10-25
Published