CVE-2016-3092: Input Validation

Published Jun 23, 2016
·
Updated

Apache Tomcat uses a package renamed copy of Apache Commons FileUpload to implement the file upload requirements of the Servlet specification. A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file. This caused the file upload process to take several orders of magnitude longer than if the boundary was the typical tens of bytes long.

External references:

http://tomcat.apache.org/security-8.html http://tomcat.apache.org/security-7.html

Upstream fixes:

Tomcat 8.5.x:

http://svn.apache.org/viewvc?view=revision&revision=1743722

Tomcat 8.0.x:

http://svn.apache.org/viewvc?view=revision&revision=1743738

Other sources

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Affected Software

103 affected componentsFixes available
maven/commons-fileupload:commons-fileupload<1.3.2
1.3.2
redhat/tomcat<7.0.70
7.0.70
redhat/tomcat<8.5.3
8.5.3
redhat/tomcat<8.0.36
8.0.36
HP IceWall Identity Manager=5.0
HP IceWall SSO Agent Option=10.0
Apache Tomcat=9.0.0-milestone1
Apache Tomcat=9.0.0-milestone3
Apache Tomcat=9.0.0-milestone4
Apache Tomcat=9.0.0-milestone6
Apache Tomcat=8.0.0-rc1
Apache Tomcat=8.0.0-rc10
Apache Tomcat=8.0.0-rc2
Apache Tomcat=8.0.0-rc5
Apache Tomcat=8.0.1
Apache Tomcat=8.0.3
Apache Tomcat=8.0.5
Apache Tomcat=8.0.8
Apache Tomcat=8.0.11
Apache Tomcat=8.0.12
Apache Tomcat=8.0.14
Apache Tomcat=8.0.15
Apache Tomcat=8.0.17
Apache Tomcat=8.0.18
Apache Tomcat=8.0.20
Apache Tomcat=8.0.21
Apache Tomcat=8.0.22
Apache Tomcat=8.0.23
Apache Tomcat=8.0.24
Apache Tomcat=8.0.26
Apache Tomcat=8.0.27
Apache Tomcat=8.0.28
Apache Tomcat=8.0.29
Apache Tomcat=8.0.30
Apache Tomcat=8.0.32
Apache Tomcat=8.0.33
Apache Tomcat=8.0.35
Debian Debian Linux=8.0
Apache Tomcat=8.5.0
Apache Tomcat=8.5.2
Apache Commons Fileupload<=1.3.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Apache Tomcat=7.0.0
Apache Tomcat=7.0.0-beta
Apache Tomcat=7.0.1
Apache Tomcat=7.0.2
Apache Tomcat=7.0.2-beta
Apache Tomcat=7.0.4
Apache Tomcat=7.0.4-beta
Apache Tomcat=7.0.5
Apache Tomcat=7.0.5-beta
Apache Tomcat=7.0.6
Apache Tomcat=7.0.8
Apache Tomcat=7.0.10
Apache Tomcat=7.0.11
Apache Tomcat=7.0.12
Apache Tomcat=7.0.14
Apache Tomcat=7.0.16
Apache Tomcat=7.0.19
Apache Tomcat=7.0.20
Apache Tomcat=7.0.21
Apache Tomcat=7.0.22
Apache Tomcat=7.0.23
Apache Tomcat=7.0.25
Apache Tomcat=7.0.26
Apache Tomcat=7.0.27
Apache Tomcat=7.0.28
Apache Tomcat=7.0.29
Apache Tomcat=7.0.30
Apache Tomcat=7.0.32
Apache Tomcat=7.0.33
Apache Tomcat=7.0.34
Apache Tomcat=7.0.35
Apache Tomcat=7.0.37
Apache Tomcat=7.0.39
Apache Tomcat=7.0.40
Apache Tomcat=7.0.41
Apache Tomcat=7.0.42
Apache Tomcat=7.0.47
Apache Tomcat=7.0.50
Apache Tomcat=7.0.52
Apache Tomcat=7.0.53
Apache Tomcat=7.0.54
Apache Tomcat=7.0.55
Apache Tomcat=7.0.56
Apache Tomcat=7.0.57
Apache Tomcat=7.0.59
Apache Tomcat=7.0.61
Apache Tomcat=7.0.62
Apache Tomcat=7.0.63
Apache Tomcat=7.0.64
Apache Tomcat=7.0.65
Apache Tomcat=7.0.67
Apache Tomcat=7.0.68
Apache Tomcat=7.0.69
Apache Tomcat=9.0.0-m1
Apache Tomcat=9.0.0-m3
Apache Tomcat=9.0.0-m4
Apache Tomcat=9.0.0-m6
IBM InfoSphere Data Architect<=9.2.1

Event History

Jul 4, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Dec 21, 2018
Advisory Published
05:47 PM
Mar 4, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-3092?

CVE-2016-3092 is classified as a high severity vulnerability due to its potential to cause denial of service.

2

How do I fix CVE-2016-3092?

To remediate CVE-2016-3092, upgrade Apache Commons Fileupload to version 1.3.2 or later, and ensure Apache Tomcat is updated to at least version 7.0.70, 8.0.36, 8.5.3, or 9.0.0-M7.

3

What type of attack is possible with CVE-2016-3092?

CVE-2016-3092 allows remote attackers to perform denial of service attacks by sending long boundary strings that consume excessive CPU resources.

4

Which software versions are affected by CVE-2016-3092?

Affected versions include Apache Commons Fileupload prior to 1.3.2 and various Apache Tomcat versions below specified thresholds.

5

Is CVE-2016-3092 still a risk if updated software is running?

No, if the software has been updated to the fixed versions, the risk associated with CVE-2016-3092 is mitigated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203