CVE-2014-0050

Exp

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

Published: 2014-04-01 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-0050 is rated High Exploit Risk (79.9/100): CVSS High severity, with high exploitation likelihood (EPSS 92.65%, 100th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2014-0050

EDB-ID Source Kind Published Link
31615 exploit_db edb 2014-02-12 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2014-0050

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-08 92.69% 92.65% -0.04%
2 2025-11-29 92.88% 92.69% -0.19%
3 2025-09-05 92.88%

Full EPSS history (18 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-0050

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2014-0050

GitHub Security Advisory for CVE-2014-0050

GHSA-xx68-jfcg-xmmf · Severity: high · Ecosystem: maven — Commons FileUpload Denial of service vulnerability

OS Trackers for CVE-2014-0050

vendor priority summary link
debian not yet assigned CVE-2014-0050 not yet assigned priority: Debian including 1 source packages (libcommons-fileupload-java), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2014-0050
gentoo low CVE-2014-0050: 2 GLSA(s) (201412-29, 202107-39), 2 atom(s) (dev-java/commons-fileupload, www-servers/tomcat); latest impact low. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2014-0050
redhat medium https://access.redhat.com/security/cve/CVE-2014-0050
suse high https://www.suse.com/security/cve/CVE-2014-0050/
ubuntu medium CVE-2014-0050 medium priority: Ubuntu including 3 source packages (libcommons-fileupload-java, tomcat6, tomcat7), 48 status rows across 16 suites (artful, bionic, cosmic, disco, lucid, precise, quantal, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): not-affected 28, DNE 9, ignored 6, released 4, needs-triage 1. https://ubuntu.com/security/CVE-2014-0050

NVD evaluator notes for CVE-2014-0050

Comment: The previous CVSS assessment ( Base Score: 5.0 - AV:N/AC:L/AU:N/C:N/I:N/A:P) was provided at the time of initial analysis based on the best available published information at that time. The score has been updated to reflect the impact to Oracle products per <a href=http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html> Oracle Critical Patch Update Advisory - October 2015 </a>. Other products listed as vulnerable may or may not be similarly impacted.

Affected software / configurations for CVE-2014-0050

Vendor Product Version Raw CPE
oracle retail_applications 12.0 cpe:2.3:a:oracle:retail_applications:12.0:*:*:*:*:*:*:*
oracle retail_applications 12.0in cpe:2.3:a:oracle:retail_applications:12.0in:*:*:*:*:*:*:*
oracle retail_applications 13.0 cpe:2.3:a:oracle:retail_applications:13.0:*:*:*:*:*:*:*
oracle retail_applications 13.1 cpe:2.3:a:oracle:retail_applications:13.1:*:*:*:*:*:*:*
oracle retail_applications 13.2 cpe:2.3:a:oracle:retail_applications:13.2:*:*:*:*:*:*:*
oracle retail_applications 13.3 cpe:2.3:a:oracle:retail_applications:13.3:*:*:*:*:*:*:*
oracle retail_applications 13.4 cpe:2.3:a:oracle:retail_applications:13.4:*:*:*:*:*:*:*
oracle retail_applications 14.0 cpe:2.3:a:oracle:retail_applications:14.0:*:*:*:*:*:*:*
apache commons_fileupload <= 1.3 cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:*
apache commons_fileupload 1.0 cpe:2.3:a:apache:commons_fileupload:1.0:*:*:*:*:*:*:*
apache commons_fileupload 1.1 cpe:2.3:a:apache:commons_fileupload:1.1:*:*:*:*:*:*:*
apache commons_fileupload 1.1.1 cpe:2.3:a:apache:commons_fileupload:1.1.1:*:*:*:*:*:*:*
apache commons_fileupload 1.2 cpe:2.3:a:apache:commons_fileupload:1.2:*:*:*:*:*:*:*
apache commons_fileupload 1.2.1 cpe:2.3:a:apache:commons_fileupload:1.2.1:*:*:*:*:*:*:*
apache commons_fileupload 1.2.2 cpe:2.3:a:apache:commons_fileupload:1.2.2:*:*:*:*:*:*:*
apache tomcat 7.0.0 cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*
apache tomcat 7.0.0 cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
apache tomcat 7.0.1 cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*
apache tomcat 7.0.2 cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*
apache tomcat 7.0.2 cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:*
apache tomcat 7.0.3 cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*
apache tomcat 7.0.4 cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*
apache tomcat 7.0.4 cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:*
apache tomcat 7.0.5 cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:*
apache tomcat 7.0.6 cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*
apache tomcat 7.0.7 cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:*
apache tomcat 7.0.8 cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:*
apache tomcat 7.0.9 cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:*
apache tomcat 7.0.10 cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*
apache tomcat 7.0.11 cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*
apache tomcat 7.0.12 cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*
apache tomcat 7.0.13 cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:*
apache tomcat 7.0.14 cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*
apache tomcat 7.0.15 cpe:2.3:a:apache:tomcat:7.0.15:*:*:*:*:*:*:*
apache tomcat 7.0.16 cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*
apache tomcat 7.0.17 cpe:2.3:a:apache:tomcat:7.0.17:*:*:*:*:*:*:*
apache tomcat 7.0.18 cpe:2.3:a:apache:tomcat:7.0.18:*:*:*:*:*:*:*
apache tomcat 7.0.19 cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*
apache tomcat 7.0.20 cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*
apache tomcat 7.0.21 cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*
apache tomcat 7.0.22 cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*
apache tomcat 7.0.23 cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*
apache tomcat 7.0.24 cpe:2.3:a:apache:tomcat:7.0.24:*:*:*:*:*:*:*
apache tomcat 7.0.25 cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*
apache tomcat 7.0.26 cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*
apache tomcat 7.0.27 cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*
apache tomcat 7.0.28 cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*
apache tomcat 7.0.29 cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*
apache tomcat 7.0.30 cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*
apache tomcat 7.0.31 cpe:2.3:a:apache:tomcat:7.0.31:*:*:*:*:*:*:*
apache tomcat 7.0.32 cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*
apache tomcat 7.0.33 cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*
apache tomcat 7.0.34 cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*
apache tomcat 7.0.35 cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*
apache tomcat 7.0.36 cpe:2.3:a:apache:tomcat:7.0.36:*:*:*:*:*:*:*
apache tomcat 7.0.37 cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*
apache tomcat 7.0.38 cpe:2.3:a:apache:tomcat:7.0.38:*:*:*:*:*:*:*
apache tomcat 7.0.39 cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*
apache tomcat 7.0.40 cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*
apache tomcat 7.0.41 cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*
apache tomcat 7.0.42 cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*
apache tomcat 7.0.43 cpe:2.3:a:apache:tomcat:7.0.43:*:*:*:*:*:*:*
apache tomcat 7.0.44 cpe:2.3:a:apache:tomcat:7.0.44:*:*:*:*:*:*:*
apache tomcat 7.0.45 cpe:2.3:a:apache:tomcat:7.0.45:*:*:*:*:*:*:*
apache tomcat 7.0.46 cpe:2.3:a:apache:tomcat:7.0.46:*:*:*:*:*:*:*
apache tomcat 7.0.47 cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*
apache tomcat 7.0.48 cpe:2.3:a:apache:tomcat:7.0.48:*:*:*:*:*:*:*
apache tomcat 7.0.49 cpe:2.3:a:apache:tomcat:7.0.49:*:*:*:*:*:*:*
apache tomcat 7.0.50 cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*
apache tomcat 8.0.0 cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*
apache tomcat 8.0.0 cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*
apache tomcat 8.0.0 cpe:2.3:a:apache:tomcat:8.0.0:rc2:*:*:*:*:*:*
apache tomcat 8.0.0 cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*
apache tomcat 8.0.1 cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*

References for CVE-2014-0050

URL Tags
http://advisories.mageia.org/MGASA-2014-0110.html
http://blog.spiderlabs.com/2014/02/cve-2014-0050-exploit-with-boundaries-loops-without-boundaries.html Exploit
http://jvn.jp/en/jp/JVN14876762/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000017
http://mail-archives.apache.org/mod_mbox/commons-dev/201402.mbox/%3C52F373FC.9030907%40apache.org%3E
http://marc.info/?l=bugtraq&m=143136844732487&w=2
http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html
http://rhn.redhat.com/errata/RHSA-2014-0252.html
http://rhn.redhat.com/errata/RHSA-2014-0253.html
http://rhn.redhat.com/errata/RHSA-2014-0400.html
http://seclists.org/fulldisclosure/2014/Dec/23
http://secunia.com/advisories/57915
http://secunia.com/advisories/58075
http://secunia.com/advisories/58976
http://secunia.com/advisories/59039
http://secunia.com/advisories/59041
http://secunia.com/advisories/59183
http://secunia.com/advisories/59184
http://secunia.com/advisories/59185
http://secunia.com/advisories/59187
http://secunia.com/advisories/59232
http://secunia.com/advisories/59399
http://secunia.com/advisories/59492
http://secunia.com/advisories/59500
http://secunia.com/advisories/59725
http://secunia.com/advisories/60475
http://secunia.com/advisories/60753
http://svn.apache.org/r1565143 Patch
http://tomcat.apache.org/security-7.html Patch Vendor Advisory
http://tomcat.apache.org/security-8.html Patch Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21669554
http://www-01.ibm.com/support/docview.wss?uid=swg21675432
http://www-01.ibm.com/support/docview.wss?uid=swg21676091
http://www-01.ibm.com/support/docview.wss?uid=swg21676092
http://www-01.ibm.com/support/docview.wss?uid=swg21676401
http://www-01.ibm.com/support/docview.wss?uid=swg21676403
http://www-01.ibm.com/support/docview.wss?uid=swg21676405
http://www-01.ibm.com/support/docview.wss?uid=swg21676410
http://www-01.ibm.com/support/docview.wss?uid=swg21676656
http://www-01.ibm.com/support/docview.wss?uid=swg21676853
http://www-01.ibm.com/support/docview.wss?uid=swg21677691
http://www-01.ibm.com/support/docview.wss?uid=swg21677724
http://www-01.ibm.com/support/docview.wss?uid=swg21681214
http://www.debian.org/security/2014/dsa-2856
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-015/index.html
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-016/index.html
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-017/index.html
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm
http://www.mandriva.com/security/advisories?name=MDVSA-2015:084
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
http://www.securityfocus.com/archive/1/532549/100/0/threaded
http://www.securityfocus.com/archive/1/534161/100/0/threaded
http://www.securityfocus.com/bid/65400
http://www.ubuntu.com/usn/USN-2130-1
http://www.vmware.com/security/advisories/VMSA-2014-0007.html
http://www.vmware.com/security/advisories/VMSA-2014-0008.html
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
https://bugzilla.redhat.com/show_bug.cgi?id=1062337
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
https://security.gentoo.org/glsa/202107-39
cvelogic Threat Intelligence