CVE-2013-2186: Red Hat JBoss Enterprise Brms Platform
High severity, CVSS 7.5. EPSS: 12.7% chance of exploitation in the next 30 days.
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
Affected products
- Red Hat JBoss Enterprise Brms Platform: version 5.3.1 only
- Red Hat JBoss Enterprise Portal Platform: version 4.3.0 only; version 5.2.2 only; version 6.0.0 only
- Red Hat JBoss Enterprise Web Server: version 1.0.2 only
- Red Hat Openshift: up to and including 3.1
- Ubuntu Ubuntu: version 10.04 only
Published 2013-10-28. Last modified 2026-06-16.