Denial of Service Vulnerability in Apache Wicket by The Apache Software Foundation
CVE-2016-6793
9.1CRITICAL
What is CVE-2016-6793?
The DiskFileItem class in Apache Wicket versions 6.x before 6.25.0 and 1.5.x before 1.5.17 contains a vulnerability that allows remote attackers to initiate a denial of service through an infinite loop. Additionally, it enables unauthorized file operations, including writing, moving, and deletion of files using the permissions of DiskFileItem. If the application is running on a Java Virtual Machine version prior to 1.3.1, this vulnerability could also lead to the execution of arbitrary code through crafted serialized Java objects.