On this page

Atomicorp WAF Rule 330791

Rule Summary

Description

This rule detects when the request body processor, used for request body parsing, is unable to parse the body of the request. This is a serious condition, and can mean only one of two things:

1) An attacker is attempting to bypass the WAF by constructing a body that will not be parsed correctly by the WAF, in hopes of bypassing the WAF.

2) The client side application and/or server side application is generating a non-RFC compliant, or broken message body that the WAF is unable to assemble. This can occur with a broken application, broken client, buggy library or even a temporary broken connection.

False Positives

Disabling this rule will leave your system open for impedance mismatch attacks, therefore it is highly recommended you first discuss this issue with the applications developers to determine why the format of the request is unparsable, and determine if they can fix their application first. This condition is extremely rare and is almost always caused by a buggy application on the clients side. It is not recommended that you disable this rule if you have a false positive.

If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case or if its clever attack on your system. If you know this is not an attack, please provide any and all information the application developer provided that shows the request is compliant and that there is not a bug on the client side.

Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

If you know that this behaviour is acceptable for your application, you can tune it by identifying the application that is being triggered, and specifically allowing that application to generate bodies the WAF can not examine correctly. Please see the Tuning the Atomicorp WAF Rules page for basic information.

Similar Rules

WAF_330792

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2025-34040Zhiyuan OA - arbitrary file upload leadingZhiyuan OA Web Application System10.0 (v4.0)Critical
CVE-2025-23211Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCErecipes9.9 (v3.1)Critical
CVE-2013-4864MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware9.8 (v3.1)Critical
CVE-2015-4683Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager9.8 (v3.0)Critical
CVE-2015-6018ZYXEL PMG5318-B20A - OS Command Injectionpmg5318-b20a firmware9.8 (v3.0)Critical
CVE-2017-14094Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server9.8 (v3.0)Critical
CVE-2017-14097Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server9.8 (v3.0)Critical
CVE-2017-18001Trustwave SWG 11.8.0.27 - SSH Unauthorized Accesssecure web gateway9.8 (v3.0)Critical
CVE-2018-12463Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injectionfortify software security center9.8 (v3.1)Critical
CVE-2018-19276OpenMRS Platform < 2.24.0 - Insecure Object Deserializationopenmrs9.8 (v3.1)Critical
CVE-2018-20526Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversalroxy fileman9.8 (v3.0)Critical
CVE-2018-6530D-Link - Unauthenticated Remote Code Executiondir-860l firmware9.8 (v3.1)Critical
CVE-2018-7600Drupal - Remote Code Executiondrupal9.8 (v3.1)Critical
CVE-2019-17506D-Link DIR-868L/817LW - Information Disclosuredir-868l b1 firmware9.8 (v3.1)Critical
CVE-2021-21978VMware View Planner <4.6 SP1- Remote Code Executionview planner9.8 (v3.1)Critical
CVE-2021-22005VMware vCenter Server - Arbitrary File Uploadcloud foundation9.8 (v3.1)Critical
CVE-2021-24212WooCommerce Help Scout - Arbitrary File Uploadhelp scout9.8 (v3.1)Critical
CVE-2021-24499WordPress Workreap - Remote Code Executionworkreap9.8 (v3.1)Critical
CVE-2021-31805Apache Struts2 S2-062 - Remote Code Executionstruts9.8 (v3.1)Critical
CVE-2021-3378FortiLogger 4.4.2.2 - Arbitrary File Uploadfortilogger9.8 (v3.1)Critical
CVE-2022-31056GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration)glpi9.8 (v3.1)Critical
CVE-2023-2648Weaver E-Office 9.5 - Remote Code Executione-office9.8 (v3.1)Critical
CVE-2023-2734MStore API <= 3.9.1 - Authentication Bypassmstore api9.8 (v3.1)Critical
CVE-2023-34659JeecgBoot 3.5.0 - SQL Injectionjeecg boot9.8 (v3.1)Critical
CVE-2023-37629Online Piggery Management System v1.0 - Unauthenticated File Uploadsimple online piggery management system9.8 (v3.1)Critical
CVE-2024-30502WP Travel Engine <= 5.7.9 - SQL Injectionwp travel engine9.8 (v3.1)Critical
CVE-2025-2776SysAid On-Prem <= 23.3.40 - XML External Entitysysaid9.8 (v3.1)Critical
CVE-2025-2777SysAid On-Prem <= 23.3.40 - XML External Entitysysaid9.8 (v3.1)Critical
CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader - Deserializationnetweaver9.8 (v3.1)Critical
CVE-2018-1821IBM Operational Decision Manager 8.x - XML External Entity Injectionoperational decision manager9.1 (v3.0)Critical
CVE-2018-20525Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversalroxy fileman9.1 (v3.1)Critical
CVE-2021-37425Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)mobiletogether server9.1 (v3.1)Critical
CVE-2025-48703CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Executionwebpanel9.0 (v3.1)Critical
CVE-2013-4863MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware8.8 (v3.1)High
CVE-2017-11398Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server8.8 (v3.0)High
CVE-2018-1213Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon onefs8.8 (v3.0)High
CVE-2018-7357ZTE ZXHN H168N - Improper Access Restrictionszxhn h168n firmware8.8 (v3.0)High
CVE-2018-7358ZTE ZXHN H168N - Improper Access Restrictionszxhn h168n firmware8.8 (v3.0)High
CVE-2022-28080Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)event management system8.8 (v3.1)High
CVE-2022-46552D-Link DIR-846 - Remote Command Execution (RCE) vulnerabilitydir-846 firmware8.8 (v3.1)High
CVE-2023-32749Pydio Cells 4.1.2 - Unauthorised Role Assignmentscells8.8 (v3.1)High
CVE-2023-49230Peplink Balance Two before 8.4.0 - Unauthenticated Config Uploadbalance two firmware8.8 (v3.1)High
CVE-2023-50071CVE-2023-50071 - Multiple SQL Injectioncustomer support system8.8 (v3.1)High
CVE-2023-50094reNgine 2.2.0 - Command Injectionrengine8.8 (v3.1)High
CVE-2024-24809Traccar - Unrestricted File Uploadtraccar8.5 (v3.1)High
CVE-2023-47218QNAP QTS and QuTS Hero - OS Command Injectionqts8.3 (v3.1)High
CVE-2026-69101Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpointtis8.3 (v4.0)High
CVE-2013-4862MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware8.1 (v3.1)High
CVE-2017-14095Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server8.1 (v3.0)High
CVE-2019-3759RSA IG&L Aveksa 7.1.1 - Remote Code Executionrsa identity governance and lifecycle8.1 (v3.1)High
CVE-2015-4681Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager7.8 (v3.0)High
CVE-2019-20499D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High
CVE-2019-20500D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High
CVE-2019-20501D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High
CVE-2016-3473Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injectionbusiness intelligence publisher7.7 (v3.0)High
CVE-2017-7185Cesanta Mongoose OS - Use-After-Freemongoose embedded web server library7.5 (v3.0)High
CVE-2023-40211Post Grid <= 2.2.50 - Information Exposure via REST APIpost grid combo7.5 (v3.1)High
CVE-2024-38653Ivanti Avalanche SmartDeviceServer - XML External Entityavalanche7.5 (v3.1)High
CVE-2025-2775SysAid On-Prem <= 23.3.40 - XML External Entitysysaid7.5 (v3.1)High
CVE-2023-42344OpenCMS - XML external entity (XXE)opencms7.3 (v3.1)High
CVE-2015-4027Acunetix WVS 10 - Local Privilege Escalationweb vulnerability scanner7.2 (v2.0)High
CVE-2019-2616Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injectionbusiness intelligence publisher7.2 (v3.1)High
CVE-2024-5082Nexus Repository 2 - Remote Code ExecutionNexus Repository7.1 (v4.0)High
CVE-2015-4685Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager7.0 (v3.0)High
CVE-2018-1203Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon onefs6.7 (v3.0)Medium
CVE-2018-1204Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon onefs6.7 (v3.0)Medium
CVE-2013-4861MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware6.5 (v3.1)Medium
CVE-2013-4865MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware6.5 (v3.1)Medium
CVE-2015-4682Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager6.5 (v3.0)Medium
CVE-2015-4684Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager6.5 (v3.0)Medium
CVE-2017-3548Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPEpeoplesoft enterprise peopletools6.5 (v3.0)Medium
CVE-2018-7691Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2)fortify software security center6.5 (v3.0)Medium
CVE-2021-22145Elasticsearch 7.10.0-7.13.3 - Information Disclosureelasticsearch6.5 (v3.1)Medium
CVE-2023-27167Suprema BioStar 2 v2.8.16 - SQL Injectionbiostar 26.5 (v3.1)Medium
CVE-2026-12898All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Writeall-in-one-wp-migration6.5 (v3.1)Medium
CVE-2017-14096Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server6.1 (v3.0)Medium
CVE-2017-9979QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilitiesquantastor6.1 (v3.0)Medium
CVE-2021-27695openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scriptingopenmaint6.1 (v3.1)Medium
CVE-2017-14955Check_MK 1.2.8p25 - Information Disclosurecheckmk5.9 (v3.1)Medium
CVE-2021-29460Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)kirby5.4 (v3.1)Medium
CVE-2022-0020Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)cortex xsoar5.4 (v3.1)Medium
CVE-2022-34140Feehi CMS 2.1.1 - Remote Code Execution (Authenticated)feehi cms5.4 (v3.1)Medium
CVE-2022-41358Garage Management System 1.0 (categoriesName) - Stored XSSgarage management system5.4 (v3.1)Medium
CVE-2017-9978QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilitiesquantastor5.3 (v3.0)Medium
CVE-2018-1186Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium
CVE-2018-1187Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium
CVE-2018-1188Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium
CVE-2018-1189Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium
CVE-2018-1201Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium
CVE-2018-1202Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2018-7600 , CVE-2021-21978
CWE-22CVE-2025-34040 , CVE-2021-22005 , CVE-2018-20525 , CVE-2018-1204 , CVE-2013-4861 , CVE-2026-12898
CWE-27CVE-2024-24809
CWE-74CVE-2017-14094
CWE-77CVE-2023-47218
CWE-78CVE-2017-14094 , CVE-2018-6530 , CVE-2025-48703 , CVE-2022-46552 , CVE-2023-50094 , CVE-2023-47218 , CVE-2019-20499 , CVE-2019-20500 , CVE-2019-20501
CWE-79CVE-2017-14096 , CVE-2017-9979 , CVE-2021-27695 , CVE-2021-29460 , CVE-2022-0020 , CVE-2022-34140 , CVE-2022-41358 , CVE-2018-1186 , CVE-2018-1187 , CVE-2018-1188 , CVE-2018-1189 , CVE-2018-1201 , CVE-2018-1202
CWE-89CVE-2022-31056 , CVE-2023-34659 , CVE-2024-30502 , CVE-2022-28080 , CVE-2023-50071 , CVE-2023-27167
CWE-94CVE-2025-23211 , CVE-2019-3759 , CVE-2024-5082
CWE-98CVE-2017-14095
CWE-200CVE-2016-3473 , CVE-2023-40211 , CVE-2015-4682 , CVE-2021-22145 , CVE-2017-14955 , CVE-2017-9978
CWE-209CVE-2021-22145
CWE-255CVE-2015-4681 , CVE-2015-4684
CWE-264CVE-2015-4683 , CVE-2015-6018 , CVE-2015-4027 , CVE-2015-4685
CWE-285CVE-2017-11398
CWE-287CVE-2013-4863 , CVE-2018-7358
CWE-288CVE-2023-2734
CWE-306CVE-2017-18001 , CVE-2019-17506 , CVE-2018-7357
CWE-352CVE-2018-1213 , CVE-2013-4865
CWE-362CVE-2017-14955
CWE-416CVE-2017-7185
CWE-434CVE-2025-34040 , CVE-2018-20526 , CVE-2021-24212 , CVE-2021-24499 , CVE-2021-3378 , CVE-2023-2648 , CVE-2023-37629 , CVE-2025-31324 , CVE-2024-24809
CWE-502CVE-2018-19276
CWE-534CVE-2017-11398
CWE-611CVE-2018-12463 , CVE-2025-2776 , CVE-2025-2777 , CVE-2018-1821 , CVE-2021-37425 , CVE-2026-69101 , CVE-2024-38653 , CVE-2025-2775 , CVE-2023-42344 , CVE-2017-3548
CWE-732CVE-2018-1203
CWE-829CVE-2017-14095
CWE-862CVE-2021-21978 , CVE-2023-49230
CWE-863CVE-2023-32749 , CVE-2013-4862
CWE-917CVE-2021-31805
CWE-918CVE-2013-4864
CWE-1336CVE-2025-23211

Documentation Source

  • Original wiki page: WAF 330791
  • Source revision: 2378
  • Source revision date: 2012-06-15