CVE-2025-48976 Plugin 278764 - Plugin name - Apache Commons FileUpload
search cancel

CVE-2025-48976 Plugin 278764 - Plugin name - Apache Commons FileUpload

book

Article ID: 442452

calendar_today

Updated On:

Products

CA Process Automation Base

Issue/Introduction

Our security team found CVE-2025-48976 Plugin 278764 - Plugin name - Apache Commons FileUpload in ITPAM 4.4 installation:

C:\Program Files\CA\PAM\wildfly\standalone\.c2orepository\.c2oserverresources\lib\commons-fileupload-1.5.jar
C:\Program Files\CA\PAM\wildfly\standalone\deployments\c2oear-snapshot.ear\lib\commons-fileupload-1.5.jar
C:\Program Files\CA\PAM\wildfly\standalone\tmp\vfs\deployment\deployment9013d90449db04ca\commons-fileupload-1.5.jar-a5b09eeeeb3ba54f\commons-fileupload-1.5.jar

Environment

CA Process Automation 4.4

Resolution

  1. Download the attached jar file to a location on the server where PAM 4.4 runs
  2. Shutdown PAM
  3. Back up the 1.5 jar files as you mentioned
  4. Replace the 1.5 jar files by the 1.6 jar file you downloaded in step 1.
  5. Start PAM and test

Additional Information

Apache Commons FileUpload < 1.6 , 2.0.0-M1 < 2.0.0-M4 Denial of Service (CVE-2025-48976)

 

Attachments

commons-fileupload-1.6.0.jar.zip get_app