PT-2014-2568 · Red Hat+1 · Red Hat Jboss Portal+2

·

CVE-2013-2185

·

Publicado

2014-01-19

·

Atualizado

2024-08-06

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions prior to 7.0.39 Red Hat JBoss Enterprise Application Platform version 6.1.0 Red Hat JBoss Portal version 6.0.0
Description The readObject method in the DiskFileItem class allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance. This issue is similar to a previously known problem. There is a dispute regarding the responsibility for protecting against this issue, with the Apache Tomcat team and Red Hat having different views on the matter.
Recommendations For Apache Tomcat versions prior to 7.0.39, update to version 7.0.39 or later to resolve the issue. For Red Hat JBoss Enterprise Application Platform version 6.1.0, consider disabling the readObject method in the DiskFileItem class as a temporary workaround until a patch is available. For Red Hat JBoss Portal version 6.0.0, restrict access to the DiskFileItem class to minimize the risk of exploitation until a fix is provided.

Correção

Deserialization of Untrusted Data

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2185
GHSA-V6C7-8QX5-8GMP
RHSA-2013:1193

Produtos afetados

Apache Tomcat
Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Portal