CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2016-3092: icewall identity manager 5.0; +6 more affected products

CVE-2016-3092. CVSS 3.1 base score 7.5 (HIGH, Source advisory). EPSS 0.35927 (percentile 0.98434), scored 2026-10-06.

Affected technology

icewall identity manager · 5.0
hp

icewall sso agent option · 10.0
hp

tomcat · 9.0.0 · update milestone1
apache

tomcat · 9.0.0 · update milestone3
apache

tomcat · 9.0.0 · update milestone4
apache

tomcat · 9.0.0 · update milestone6
apache

tomcat · 8.0.0 · update rc1
apache

tomcat · 8.0.0 · update rc10
apache

tomcat · 8.0.0 · update rc2
apache

tomcat · 8.0.0 · update rc5
apache

tomcat · 8.0.1
apache

tomcat · 8.0.3
apache

tomcat · 8.0.5
apache

tomcat · 8.0.8
apache

tomcat · 8.0.11
apache

tomcat · 8.0.12
apache

tomcat · 8.0.14
apache

tomcat · 8.0.15
apache

tomcat · 8.0.17
apache

tomcat · 8.0.18
apache

tomcat · 8.0.20
apache

tomcat · 8.0.21
apache

tomcat · 8.0.22
apache

tomcat · 8.0.23
apache

tomcat · 8.0.24
apache

tomcat · 8.0.26
apache

tomcat · 8.0.27
apache

tomcat · 8.0.28
apache

tomcat · 8.0.29
apache

tomcat · 8.0.30
apache

tomcat · 8.0.32
apache

tomcat · 8.0.33
apache

tomcat · 8.0.35
apache

debian linux · 8.0
debian

tomcat · 8.5.0
apache

tomcat · 8.5.2
apache

commons fileupload · through 1.3.1 (inclusive)
apache

ubuntu linux · 12.04
canonical

ubuntu linux · 14.04
canonical

ubuntu linux · 15.10
canonical

ubuntu linux · 16.04
canonical

tomcat · 7.0.0
apache

tomcat · 7.0.0 · update beta
apache

tomcat · 7.0.1
apache

tomcat · 7.0.2
apache

tomcat · 7.0.2 · update beta
apache

tomcat · 7.0.4
apache

tomcat · 7.0.4 · update beta
apache

tomcat · 7.0.5
apache

tomcat · 7.0.5 · update beta
apache

tomcat · 7.0.6
apache

tomcat · 7.0.8
apache

tomcat · 7.0.10
apache

tomcat · 7.0.11
apache

tomcat · 7.0.12
apache

tomcat · 7.0.14
apache

tomcat · 7.0.16
apache

tomcat · 7.0.19
apache

tomcat · 7.0.20
apache

tomcat · 7.0.21
apache

tomcat · 7.0.22
apache

tomcat · 7.0.23
apache

tomcat · 7.0.25
apache

tomcat · 7.0.26
apache

tomcat · 7.0.27
apache

tomcat · 7.0.28
apache

tomcat · 7.0.29
apache

tomcat · 7.0.30
apache

tomcat · 7.0.32
apache

tomcat · 7.0.33
apache

tomcat · 7.0.34
apache

tomcat · 7.0.35
apache

tomcat · 7.0.37
apache

tomcat · 7.0.39
apache

tomcat · 7.0.40
apache

tomcat · 7.0.41
apache

tomcat · 7.0.42
apache

tomcat · 7.0.47
apache

tomcat · 7.0.50
apache

tomcat · 7.0.52
apache

tomcat · 7.0.53
apache

tomcat · 7.0.54
apache

tomcat · 7.0.55
apache

tomcat · 7.0.56
apache

tomcat · 7.0.57
apache

tomcat · 7.0.59
apache

tomcat · 7.0.61
apache

tomcat · 7.0.62
apache

tomcat · 7.0.63
apache

tomcat · 7.0.64
apache

tomcat · 7.0.65
apache

tomcat · 7.0.67
apache

tomcat · 7.0.68
apache

tomcat · 7.0.69
apache

n/a · n/a
Vendor not specified by the source

Description’s affected range: before 1.3.2

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Remote attackers can cause a denial of service (CPU consumption) via a long boundary string. Source advisory’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-20
CCR priority
39.0 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Source advisory
EPSS
0.35927 · percentile 0.98434 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2016-3092.html