CVE-2013-2186 is an arbitrary file write vulnerability in the DiskFileItem class of Apache Commons FileUpload. The flaw arises from improper handling of a NULL byte embedded in a file name within a serialized DiskFileItem instance. When a vulnerable application deserializes a crafted object, the filename handling can be truncated or misinterpreted, allowing an attacker to cause data to be written to an unintended file path. The issue affected Apache Commons FileUpload as used by products including Red Hat JBoss BRMS 5.3.1, JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0, and Red Hat JBoss Web Server 1.0.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a Java-based exploit tool (ACEDcup) for generating payloads targeting the Java deserialization vulnerability in Apache Commons FileUpload (CVE-2013-2186) and Oracle JDK <7u40. The exploit consists of two main Java files: 'CommUploadSer.java' (handles creation and serialization of a malicious FileItem object) and 'Exploit.java' (the main entry point, which reads a payload file, sets the target file path, and outputs a serialized payload). The tool allows an attacker to craft a serialized Java object that, when deserialized by a vulnerable server, writes arbitrary content to an arbitrary file path on the server. The README provides usage instructions and highlights the ability to perform NTLM relay/sniffing attacks on Windows by specifying UNC paths. The repository is structured as a Maven project and includes dependencies on commons-fileupload and commons-io. No hardcoded network endpoints are present, but file paths (including UNC paths) are attacker-controlled and fingerprintable. The exploit is a proof-of-concept payload generator and does not include a server-side exploit or post-exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.