PT-2014-2568 · Apache+1 · Apache Tomcat+2
David Jorm
·
Published
2014-01-19
·
Updated
2024-08-06
·
CVE-2013-2185
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions prior to 7.0.39
Red Hat JBoss Enterprise Application Platform version 6.1.0
Red Hat JBoss Portal version 6.0.0
Description
The
readObject method in the DiskFileItem class allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance. This issue is similar to a previously known problem. There is a dispute regarding the responsibility for protecting against this issue, with the Apache Tomcat team and Red Hat having different views on the matter.Recommendations
For Apache Tomcat versions prior to 7.0.39, update to version 7.0.39 or later to resolve the issue.
For Red Hat JBoss Enterprise Application Platform version 6.1.0, consider disabling the
readObject method in the DiskFileItem class as a temporary workaround until a patch is available.
For Red Hat JBoss Portal version 6.0.0, restrict access to the DiskFileItem class to minimize the risk of exploitation until a fix is provided.Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tomcat
Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Portal