CVE Vulnerabilities

CVE-2014-0050

Published: Apr 01, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loops intended exit conditions.

Affected Software

NameVendorStart VersionEnd Version
Retail_applicationsOracle12.0 (including)12.0 (including)
Retail_applicationsOracle12.0in (including)12.0in (including)
Retail_applicationsOracle13.0 (including)13.0 (including)
Retail_applicationsOracle13.1 (including)13.1 (including)
Retail_applicationsOracle13.2 (including)13.2 (including)
Retail_applicationsOracle13.3 (including)13.3 (including)
Retail_applicationsOracle13.4 (including)13.4 (including)
Retail_applicationsOracle14.0 (including)14.0 (including)
Fuse ESB Enterprise 7.1.0RedHat*
Fuse Management Console 7.1.0RedHat*
Fuse MQ Enterprise 7.1.0RedHat*
Red Hat Enterprise Linux 6RedHattomcat6-0:6.0.24-64.el6_5*
Red Hat JBoss A-MQ 6.1RedHat*
Red Hat JBoss BPMS 6.0RedHatjbossweb*
Red Hat JBoss BRMS 6.0RedHatjbossweb*
Red Hat JBoss Enterprise Application Platform 6.2RedHatjbossweb*
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5RedHatjbossweb-0:7.3.0-2.Final_redhat_2.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6RedHatjbossweb-0:7.3.0-2.Final_redhat_2.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHattomcat6-0:6.0.37-19_patch_04.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHattomcat7-0:7.0.40-13_patch_02.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat6-0:6.0.37-27_patch_04.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat7-0:7.0.40-9_patch_02.ep6.el6*
Red Hat JBoss Fuse 6.1RedHat*
Red Hat JBoss Fuse Service Works 6.0RedHatjbossweb*
Red Hat JBoss Operations Network 3.2RedHat*
Red Hat JBoss Portal 6.2RedHatjbossweb*
Red Hat JBoss Web Server 2.0RedHattomcat7*
Red Hat JBoss Web Server 2.0RedHattomcat6*
Libcommons-fileupload-javaUbuntulucid*
Libcommons-fileupload-javaUbuntuprecise*
Libcommons-fileupload-javaUbuntuquantal*
Libcommons-fileupload-javaUbuntusaucy*
Libcommons-fileupload-javaUbuntutrusty*
Libcommons-fileupload-javaUbuntuupstream*
Libcommons-fileupload-javaUbuntuutopic*
Tomcat7Ubuntuprecise*
Tomcat7Ubuntuquantal*
Tomcat7Ubuntusaucy*
Tomcat7Ubuntuupstream*

References