漏洞信息详情
Apache Commons FileUpload 访问控制错误漏洞
漏洞简介
Apache Commons FileUpload是美国阿帕奇(Apache)基金会的一个可将文件上传到Servlet和Web应用程序的软件包。
Apache Commons FileUpload 1.3.3之前版本中存在访问控制错误漏洞。该漏洞源于网络系统或产品未正确限制来自未授权角色的资源访问。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,详情请关注厂商主页:
http://commons.apache.org/
参考网址
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
来源:N/A
链接:https://www.oracle.com/security-alerts/cpuapr2020.html
来源:BID
链接:http://www.securityfocus.com/bid/93604
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2020.html
来源:MLIST
链接:https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
来源:MISC
链接:https://www.tenable.com/security/research/tra-2016-23
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
来源:MLIST
链接:https://lists.apache.org/thread.html/d66657323fd25e437face5e84899c8ca404ccd187e81c3f2fa8b6080@%3Cannounce.apache.org%3E
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20190212-0001/
来源:MISC
链接:http://www.zerodayinitiative.com/advisories/ZDI-16-570/
来源:CONFIRM
链接:https://issues.apache.org/jira/browse/FILEUPLOAD-279
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00036.html
来源:BID
链接:https://www.securityfocus.com/bid/93604
来源:www.netiq.com
链接:https://www.netiq.com/support/kb/doc.php?id=7018113
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg22010587
来源:www.oracle.com
链接:https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
来源:www.oracle.com
链接:https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2016-1000031
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1393454
来源:www.novell.com
链接:http://www.novell.com/
来源:www.netiq.com
链接:https://www.netiq.com/products/sentinel/
来源:MISC
链接:https://www.tenable.com/security/research/tra-2016-30
来源:MISC
链接:https://www.tenable.com/security/research/tra-2016-12
来源:CONFIRM
链接:http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
来源:CONFIRM
链接:https://issues.apache.org/jira/browse/WW-4812
来源:MISC
链接:https://www.oracle.com/security-alerts/cpujul2020.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=swg22014121
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10887987
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10887995
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10887989
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10887985
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10887991
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10872142
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191212-1.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10870454
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75922
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujul2020.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80706
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2536/
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2021.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-apache-commons-fileupload-publicly-disclosed-vulnerability-in-ibm-ediscovery-manager/
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2020verbose.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cognos-business-intelligence-has-addressed-multiple-vulnerabilities-q12021/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2018.0660.10/
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2020.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-identified-in-ibm-storediq/
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cognos-analytics-has-addressed-multiple-vulnerabilities-3/
来源:www-01.ibm.com
链接:https://www-01.ibm.com/support/docview.wss?uid=ibm10872142
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/93604
受影响实体
- Apache Commons_fileupload:1.3.2<!--2000-1-1-->
补丁
- NetIQ Sentinel 安全漏洞的修复措施<!--2016-10-19-->
还没有评论,来说两句吧...