suse · CVE-2016-3092

Quick triage

Priority: high Published: 2021-05-30 13:40:21 UTC Updated: 2026-04-18 17:57:03 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-3092 severity important: SUSE including 363 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 514 product×package rows across 56 product lines (HPE Helion OpenStack 8, SUSE CaaS Platform 4.0, … (56 product lines)): Known Affected 231, Fixed 187, Known Not Affected 96.

Description:

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

cvelogic Threat Intelligence