CVE-2016-3092EPSS p98.5%
CVE-2016-3092CVE-2016-3092
hp / icewall_identity_manager
Description
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 37.17% probability of exploitation · percentile 98.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |