PT-2014-2568 · Apache+1 · Apache Tomcat+2

David Jorm

·

Published

2014-01-19

·

Updated

2024-08-06

·

CVE-2013-2185

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions prior to 7.0.39 Red Hat JBoss Enterprise Application Platform version 6.1.0 Red Hat JBoss Portal version 6.0.0
Description The readObject method in the DiskFileItem class allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance. This issue is similar to a previously known problem. There is a dispute regarding the responsibility for protecting against this issue, with the Apache Tomcat team and Red Hat having different views on the matter.
Recommendations For Apache Tomcat versions prior to 7.0.39, update to version 7.0.39 or later to resolve the issue. For Red Hat JBoss Enterprise Application Platform version 6.1.0, consider disabling the readObject method in the DiskFileItem class as a temporary workaround until a patch is available. For Red Hat JBoss Portal version 6.0.0, restrict access to the DiskFileItem class to minimize the risk of exploitation until a fix is provided.

Fix

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2013-2185
GHSA-V6C7-8QX5-8GMP
RHSA-2013:1193

Affected Products

Apache Tomcat
Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Portal