---
id: CVE-2016-3092
title: >-
  The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used
  in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and
  9.x before 9.0.0.M7 and other products, allows remote attackers to cause a
  denial…
summary: >-
  The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used
  in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and
  9.x before 9.0.0.M7 and other products, allows remote attackers to cause a
  denial…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: hp
product: icewall_identity_manager
affected:
  - icewall_identity_manager = 5.0
  - icewall_sso_agent_option = 10.0
  - tomcat = 9.0.0
  - tomcat = 8.0.0
  - tomcat = 8.0.1
  - tomcat = 8.0.3
  - tomcat = 8.0.5
  - tomcat = 8.0.8
  - tomcat = 8.0.11
  - tomcat = 8.0.12
  - tomcat = 8.0.14
  - tomcat = 8.0.15
  - tomcat = 8.0.17
  - tomcat = 8.0.18
  - tomcat = 8.0.20
  - tomcat = 8.0.21
  - tomcat = 8.0.22
  - tomcat = 8.0.23
  - tomcat = 8.0.24
  - tomcat = 8.0.26
  - tomcat = 8.0.27
  - tomcat = 8.0.28
  - tomcat = 8.0.29
  - tomcat = 8.0.30
  - tomcat = 8.0.32
  - tomcat = 8.0.33
  - tomcat = 8.0.35
  - debian_linux = 8.0
  - tomcat = 8.5.0
  - tomcat = 8.5.2
  - commons_fileupload <= 1.3.1
  - ubuntu_linux = 12.04
  - ubuntu_linux = 14.04
  - ubuntu_linux = 15.10
  - ubuntu_linux = 16.04
  - tomcat = 7.0.0
  - tomcat = 7.0.1
  - tomcat = 7.0.2
  - tomcat = 7.0.4
  - tomcat = 7.0.5
  - tomcat = 7.0.6
  - tomcat = 7.0.8
  - tomcat = 7.0.10
  - tomcat = 7.0.11
  - tomcat = 7.0.12
  - tomcat = 7.0.14
  - tomcat = 7.0.16
  - tomcat = 7.0.19
  - tomcat = 7.0.20
  - tomcat = 7.0.21
  - tomcat = 7.0.22
  - tomcat = 7.0.23
  - tomcat = 7.0.25
  - tomcat = 7.0.26
  - tomcat = 7.0.27
  - tomcat = 7.0.28
  - tomcat = 7.0.29
  - tomcat = 7.0.30
  - tomcat = 7.0.32
  - tomcat = 7.0.33
  - tomcat = 7.0.34
  - tomcat = 7.0.35
  - tomcat = 7.0.37
  - tomcat = 7.0.39
  - tomcat = 7.0.40
  - tomcat = 7.0.41
  - tomcat = 7.0.42
  - tomcat = 7.0.47
  - tomcat = 7.0.50
  - tomcat = 7.0.52
  - tomcat = 7.0.53
  - tomcat = 7.0.54
  - tomcat = 7.0.55
  - tomcat = 7.0.56
  - tomcat = 7.0.57
  - tomcat = 7.0.59
  - tomcat = 7.0.61
  - tomcat = 7.0.62
  - tomcat = 7.0.63
  - tomcat = 7.0.64
  - tomcat = 7.0.65
  - tomcat = 7.0.67
  - tomcat = 7.0.68
  - tomcat = 7.0.69
published: '2016-07-04'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:07.770'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-3092'
references:
  - url: 'http://jvn.jp/en/jp/JVN89379547/index.html'
    label: secalert@redhat.com
  - url: 'http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121'
    label: secalert@redhat.com
  - url: 'http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.html'
    label: secalert@redhat.com
  - url: >-
      http://mail-archives.apache.org/mod_mbox/commons-dev/201606.mbox/%3CCAF8HOZ%2BPq2QH8RnxBuJyoK1dOz6jrTiQypAC%2BH8g6oZkBg%2BCxg%40mail.gmail.com%3E
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2068.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2069.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2070.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2071.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2072.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2599.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2807.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2808.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2017-0457.html'
    label: secalert@redhat.com
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743480'
    label: secalert@redhat.com
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743722'
    label: secalert@redhat.com
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743738'
    label: secalert@redhat.com
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743742'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-7.html'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-8.html'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-9.html'
    label: secalert@redhat.com
  - url: 'http://www.debian.org/security/2016/dsa-3609'
    label: secalert@redhat.com
  - url: 'http://www.debian.org/security/2016/dsa-3611'
    label: secalert@redhat.com
  - url: 'http://www.debian.org/security/2016/dsa-3614'
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/91453'
    label: secalert@redhat.com
  - url: 'http://www.securitytracker.com/id/1036427'
    label: secalert@redhat.com
  - url: 'http://www.securitytracker.com/id/1036900'
    label: secalert@redhat.com
  - url: 'http://www.securitytracker.com/id/1037029'
    label: secalert@redhat.com
  - url: 'http://www.securitytracker.com/id/1039606'
    label: secalert@redhat.com
  - url: 'http://www.ubuntu.com/usn/USN-3024-1'
    label: secalert@redhat.com
  - url: 'http://www.ubuntu.com/usn/USN-3027-1'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:0455'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:0456'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1349468'
    label: secalert@redhat.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05204371
    label: secalert@redhat.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289840
    label: secalert@redhat.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/201705-09'
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/202107-39'
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20190212-0001/'
    label: secalert@redhat.com
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: secalert@redhat.com
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: secalert@redhat.com
  - url: 'http://jvn.jp/en/jp/JVN89379547/index.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://mail-archives.apache.org/mod_mbox/commons-dev/201606.mbox/%3CCAF8HOZ%2BPq2QH8RnxBuJyoK1dOz6jrTiQypAC%2BH8g6oZkBg%2BCxg%40mail.gmail.com%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2068.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2069.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2070.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2071.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2072.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2599.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2807.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2808.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2017-0457.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743480'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743722'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743738'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1743742'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-7.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-8.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-9.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2016/dsa-3609'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2016/dsa-3611'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2016/dsa-3614'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/91453'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1036427'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1036900'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1037029'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1039606'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ubuntu.com/usn/USN-3024-1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ubuntu.com/usn/USN-3027-1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:0455'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:0456'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1349468'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05204371
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289840
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/201705-09'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202107-39'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190212-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-06-04T19:07:16.257844Z'
epss: 0.35927
epssPercentile: 0.98437
ingestedAt: '2026-10-07T18:42:20.870Z'
---

## Overview

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

## Affected

- `icewall_identity_manager = 5.0`
- `icewall_sso_agent_option = 10.0`
- `tomcat = 9.0.0`
- `tomcat = 8.0.0`
- `tomcat = 8.0.1`
- `tomcat = 8.0.3`
- `tomcat = 8.0.5`
- `tomcat = 8.0.8`
- `tomcat = 8.0.11`
- `tomcat = 8.0.12`
- `tomcat = 8.0.14`
- `tomcat = 8.0.15`
- `tomcat = 8.0.17`
- `tomcat = 8.0.18`
- `tomcat = 8.0.20`
- `tomcat = 8.0.21`
- `tomcat = 8.0.22`
- `tomcat = 8.0.23`
- `tomcat = 8.0.24`
- `tomcat = 8.0.26`
- `tomcat = 8.0.27`
- `tomcat = 8.0.28`
- `tomcat = 8.0.29`
- `tomcat = 8.0.30`
- `tomcat = 8.0.32`
- `tomcat = 8.0.33`
- `tomcat = 8.0.35`
- `debian_linux = 8.0`
- `tomcat = 8.5.0`
- `tomcat = 8.5.2`
- `commons_fileupload <= 1.3.1`
- `ubuntu_linux = 12.04`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 15.10`
- `ubuntu_linux = 16.04`
- `tomcat = 7.0.0`
- `tomcat = 7.0.1`
- `tomcat = 7.0.2`
- `tomcat = 7.0.4`
- `tomcat = 7.0.5`
- `tomcat = 7.0.6`
- `tomcat = 7.0.8`
- `tomcat = 7.0.10`
- `tomcat = 7.0.11`
- `tomcat = 7.0.12`
- `tomcat = 7.0.14`
- `tomcat = 7.0.16`
- `tomcat = 7.0.19`
- `tomcat = 7.0.20`
- `tomcat = 7.0.21`
- `tomcat = 7.0.22`
- `tomcat = 7.0.23`
- `tomcat = 7.0.25`
- `tomcat = 7.0.26`
- `tomcat = 7.0.27`
- `tomcat = 7.0.28`
- `tomcat = 7.0.29`
- `tomcat = 7.0.30`
- `tomcat = 7.0.32`
- `tomcat = 7.0.33`
- `tomcat = 7.0.34`
- `tomcat = 7.0.35`
- `tomcat = 7.0.37`
- `tomcat = 7.0.39`
- `tomcat = 7.0.40`
- `tomcat = 7.0.41`
- `tomcat = 7.0.42`
- `tomcat = 7.0.47`
- `tomcat = 7.0.50`
- `tomcat = 7.0.52`
- `tomcat = 7.0.53`
- `tomcat = 7.0.54`
- `tomcat = 7.0.55`
- `tomcat = 7.0.56`
- `tomcat = 7.0.57`
- `tomcat = 7.0.59`
- `tomcat = 7.0.61`
- `tomcat = 7.0.62`
- `tomcat = 7.0.63`
- `tomcat = 7.0.64`
- `tomcat = 7.0.65`
- `tomcat = 7.0.67`
- `tomcat = 7.0.68`
- `tomcat = 7.0.69`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
