Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed, resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
All Mediation Manager Releases
You must upgrade to 22.2.7 once it is released to resolve this vulnerability.
DX NetOps 22.2.7 will release Tomcat 9.0.71.
DX NetOps 22.2.7 is due out in late March but is subject to change.
There is, unfortunately, no workaround for this issue.