Interstage Application Server, Interstage Apworks, Interstage Interaction Manager, Interstage Studio: Apache Commons Fileupload vulnerability causes Denial of Service (CVE-2016-3092). August 9th, 2016


Notes on using this web page

1. Description

Apache Commons Fileupload contains a vulnerability which causes Denial of Service.

Not all computers are exposed to the threat of the vulnerability even if the corresponding product is installed.
There is a possibility of this vulnerability affecting the computer in which the product is installed if Struts1 is enabled and used in a Web application.

This vulnerability exists when the web application can receive multipart requests.


For the solution, please refer to "3-3. Workaround".

2. Impact

This vulnerability allows a malicious user to exhaust the Web application's CPU resources. It may result in a DoS attack against the server.

3. Affected systems and corresponding action

3-1. Affected systems:

GP7000F, PRIMEPOWER, PRIMERGY, GP5000, CELSIUS, AT compatible machine, PRIMEQUEST, SPARC Enterprise, Fujitsu SPARC Servers

3-2. Affected products and required patch

Interstage Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Application Server Enterprise EditionV7.0L10RHEL-AS4(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.0RHEL-AS4(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.1RHEL-AS4(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.2RHEL-AS4(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0ARHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.2.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.0.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.2.0RHEL-AS4(IPF)/ RHEL5(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.2.0RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.3.1RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV10.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV11.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.2.0RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.3.1RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV10.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV11.0.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV6.0L10RHEL-AS3(x86)/ RHEL-ES3(x86)FJSVapcstNone*
Interstage Application Server Enterprise EditionV7.0L10RHEL-AS3(x86)/ RHEL-ES3(x86)FJSVapcstNone*
Interstage Application Server Enterprise EditionV7.0L11RHEL-AS3(x86)/ RHEL-ES3(x86)/ RHEL-AS4(x86)FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.2RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0BRHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.2.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.3.1RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV10.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV11.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server PlusV7.0L10RHEL-AS3(x86)/ RHEL-ES3(x86)FJSVapcstNone*
Interstage Application Server PlusV7.0L11RHEL-AS3(x86)/ RHEL-ES3(x86)/ RHEL-AS4(x86)FJSVapcstNone*
Interstage Application Server Standard-J EditionV8.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstNone*
Interstage Application Server Standard-J EditionV8.0.2RHEL-AS4(x86)/ RHEL-AS4(EM64T)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.0.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0BRHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.2.0RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.3.1RHEL-AS4(x86)/ RHEL-AS4(EM64T)/ RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV10.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Standard-J EditionV11.0.0RHEL5(x86)/ RHEL5(Intel64)/ RHEL6(x86)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Application Server Enterprise EditionV6.0.0Solaris 7/ Solaris 8/ Solaris 9FJSVapcstNone*
Interstage Application Server Enterprise EditionV7.0.0Solaris 8/ Solaris 9FJSVapcstNone*
Interstage Application Server Enterprise EditionV7.0.1Solaris 8/ Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.2Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0BSolaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0BSolaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.2.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV10.0.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Enterprise EditionV11.0.0Solaris 10/ Solaris 11FJSVapcstNone*
Interstage Application Server PlusV7.0.0Solaris 8/ Solaris 9FJSVapcstNone*
Interstage Application Server PlusV7.0.1Solaris 8/ Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV8.0.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV8.0.2Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.0.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0BSolaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.2.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV10.0.0Solaris 9/ Solaris 10FJSVapcstNone*
Interstage Application Server Standard-J EditionV11.0.0Solaris 10/ Solaris 11FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.0Windows Server 2003(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0Windows Server 2003(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.2.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.0.0Windows Server 2003(IPF)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.2.0Windows Server 2003(IPF)/ Windows Server 2008(IPF)FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008FJSVapcstNone*
Interstage Application Server Enterprise EditionV10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV11.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2/ Windows Server 2012FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008FJSVapcstNone*
Interstage Application Server Standard-J EditionV10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV11.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows Server 2008 R2/ Windows Server 2012FJSVapcstNone*
Interstage Application Server Enterprise EditionV6.0L10Windows NT Server / Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV7.0L10Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV7.0L11Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.1Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV8.0.2Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.0.0AWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.1.0BWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV9.2.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Enterprise EditionV11.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Server 2012/ Windows Server 2012 R2FJSVapcstNone*
Interstage Application Server PlusV6.0L10Windows NT Server / Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server PlusV7.0L10Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server PlusV7.0L11Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Plus DeveloperV6.0L10Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstNone*
Interstage Application Server Plus DeveloperV7.0L10Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstNone*
Interstage Application Server Standard-J EditionV8.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV8.0.1Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV8.0.2Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.0.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.0.0AWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.0.0BWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.1.0BWindows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV9.2.0Windows 2000 Server / Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2FJSVapcstNone*
Interstage Application Server Standard-J EditionV11.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Server 2012/ Windows Server 2012 R2FJSVapcstNone*
Interstage Apworks
ProductsVersionTarget OSPackage namePatch ID.
Interstage Apworks Modelers-J EditionV6.0L10Windows 98/ Windows Me/ Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstNone*
Interstage Apworks Modelers-J EditionV6.0L10AWindows 98/ Windows Me/ Windows XP/ Windows NT/ Windows 2000/ Windows Server 2003FJSVapcstNone*
Interstage Apworks Modelers-J EditionV7.0L11Windows 98/ Windows Me/ Windows XP/ Windows 2000/ Windows Server 2003FJSVapcstNone*
Interstage Interaction Manager
ProductsVersionTarget OSPackage namePatch ID.
Interstage Interaction ManagerV10.1.0RHEL5(Intel64)/ RHEL6(Intel64)FJSVapcstNone*
Interstage Interaction ManagerV10.1.0Windows Server 2008 R2/ Windows Server 2012/ Windows Server 2012 R2FJSVapcstNone*
Interstage Studio
ProductsVersionTarget OSPackage namePatch ID.
Interstage Studio Enterprise EditionV8.0.1Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstNone*
Interstage Studio Enterprise EditionV9.0.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstNone*
Interstage Studio Enterprise EditionV9.1.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstNone*
Interstage Studio Enterprise EditionV9.1.0BWindows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstNone*
Interstage Studio Enterprise EditionV9.2.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7FJSVapcstNone*
Interstage Studio Standard-J EditionV8.0.1Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstNone*
Interstage Studio Standard-J EditionV9.0.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows VistaFJSVapcstNone*
Interstage Studio Standard-J EditionV9.1.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstNone*
Interstage Studio Standard-J EditionV9.1.0BWindows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008FJSVapcstNone*
Interstage Studio Standard-J EditionV9.2.0Windows XP/ Windows 2000/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7FJSVapcstNone*
Interstage Studio Standard-J EditionV10.0.0Windows XP/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7FJSVapcstNone*
Interstage Studio Standard-J EditionV11.0.0Windows XP/ Windows Server 2003/ Windows Vista/ Windows Server 2008/ Windows 7/ Windows Server 2012/ Windows 8FJSVapcstNone*

For the solution, please refer to "3-3. Workaround".



Note: Determining the affected product
Please confirm the version of the product by "Software manual" appended to the product.

3-3. Workaround

  1. Restrict the permitted maximum size of HTTP request header values to 2048 by Interstage HTTP Server's LimitRequestFieldSize directive or by Interstage Java EE 6's buffer-size-bytes property.
  2. Blocking multipart requests by WAFs(Web Application Firewall) or Interstage HTTP Server's RewriteCond directive if the web application does not need multipart requests.
  3. Delete commons-fileupload.jar from CLASSPATH entries if the web application does not need multipart requests.
  4. Get commons-fileupload-1.3.2.jar from Apache Software Foundation, and set it to CLASSPATH entries instead of the old commons-fileupload.jar. Moreover, get commons-io.jar from Apache Software Foundation, and add it to CLASSPATH entries if commons-io.jar does not exist in CLASSPATH entries.

4. Related information

5. Revision history

  • August 9th, 2016 :
    • Update "3-2. Affected products and required patch".
    • Add workarounds to "3-3. Workaround".
  • July 7th, 2016: Initial release

Top of Page