On this page
Atomicorp WAF Rule 330791
Rule Summary
- Rule ID: 330791
- Status: Active
- Alert message: Failed to parse request body. This may be an impedence mismatch attack, a broken application or a broken connection. This is not a false positive. Check your application or client for errors.
- Observed CWEs: CWE-20 (2), CWE-22 (6), CWE-27 (1), CWE-74 (1), CWE-77 (1), CWE-78 (9), CWE-79 (13), CWE-89 (6), CWE-94 (3), CWE-98 (1), CWE-200 (6), CWE-209 (1), CWE-255 (2), CWE-264 (4), CWE-285 (1), CWE-287 (2), CWE-288 (1), CWE-306 (3), CWE-352 (2), CWE-362 (1), CWE-416 (1), CWE-434 (9), CWE-502 (1), CWE-534 (1), CWE-611 (10), CWE-732 (1), CWE-829 (1), CWE-862 (2), CWE-863 (2), CWE-917 (1), CWE-918 (1), CWE-1336 (1)
- Revision: 3
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Rule action: deny
- HTTP status: 400
- Public tags: no_ar
- Logging: log, auditlog
Description
This rule detects when the request body processor, used for request body parsing, is unable to parse the body of the request. This is a serious condition, and can mean only one of two things:
1) An attacker is attempting to bypass the WAF by constructing a body that will not be parsed correctly by the WAF, in hopes of bypassing the WAF.
2) The client side application and/or server side application is generating a non-RFC compliant, or broken message body that the WAF is unable to assemble. This can occur with a broken application, broken client, buggy library or even a temporary broken connection.
False Positives
Disabling this rule will leave your system open for impedance mismatch attacks, therefore it is highly recommended you first discuss this issue with the applications developers to determine why the format of the request is unparsable, and determine if they can fix their application first. This condition is extremely rare and is almost always caused by a buggy application on the clients side. It is not recommended that you disable this rule if you have a false positive.
If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case or if its clever attack on your system. If you know this is not an attack, please provide any and all information the application developer provided that shows the request is compliant and that there is not a bug on the client side.
Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Tuning Guidance
If you know that this behaviour is acceptable for your application, you can tune it by identifying the application that is being triggered, and specifically allowing that application to generate bodies the WAF can not examine correctly. Please see the Tuning the Atomicorp WAF Rules page for basic information.
Similar Rules
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-34040 | Zhiyuan OA - arbitrary file upload leading | Zhiyuan OA Web Application System | 10.0 (v4.0) | Critical |
| CVE-2025-23211 | Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE | recipes | 9.9 (v3.1) | Critical |
| CVE-2013-4864 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 9.8 (v3.1) | Critical |
| CVE-2015-4683 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 9.8 (v3.0) | Critical |
| CVE-2015-6018 | ZYXEL PMG5318-B20A - OS Command Injection | pmg5318-b20a firmware | 9.8 (v3.0) | Critical |
| CVE-2017-14094 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 (v3.0) | Critical |
| CVE-2017-14097 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 (v3.0) | Critical |
| CVE-2017-18001 | Trustwave SWG 11.8.0.27 - SSH Unauthorized Access | secure web gateway | 9.8 (v3.0) | Critical |
| CVE-2018-12463 | Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection | fortify software security center | 9.8 (v3.1) | Critical |
| CVE-2018-19276 | OpenMRS Platform < 2.24.0 - Insecure Object Deserialization | openmrs | 9.8 (v3.1) | Critical |
| CVE-2018-20526 | Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal | roxy fileman | 9.8 (v3.0) | Critical |
| CVE-2018-6530 | D-Link - Unauthenticated Remote Code Execution | dir-860l firmware | 9.8 (v3.1) | Critical |
| CVE-2018-7600 | Drupal - Remote Code Execution | drupal | 9.8 (v3.1) | Critical |
| CVE-2019-17506 | D-Link DIR-868L/817LW - Information Disclosure | dir-868l b1 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-21978 | VMware View Planner <4.6 SP1- Remote Code Execution | view planner | 9.8 (v3.1) | Critical |
| CVE-2021-22005 | VMware vCenter Server - Arbitrary File Upload | cloud foundation | 9.8 (v3.1) | Critical |
| CVE-2021-24212 | WooCommerce Help Scout - Arbitrary File Upload | help scout | 9.8 (v3.1) | Critical |
| CVE-2021-24499 | WordPress Workreap - Remote Code Execution | workreap | 9.8 (v3.1) | Critical |
| CVE-2021-31805 | Apache Struts2 S2-062 - Remote Code Execution | struts | 9.8 (v3.1) | Critical |
| CVE-2021-3378 | FortiLogger 4.4.2.2 - Arbitrary File Upload | fortilogger | 9.8 (v3.1) | Critical |
| CVE-2022-31056 | GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration) | glpi | 9.8 (v3.1) | Critical |
| CVE-2023-2648 | Weaver E-Office 9.5 - Remote Code Execution | e-office | 9.8 (v3.1) | Critical |
| CVE-2023-2734 | MStore API <= 3.9.1 - Authentication Bypass | mstore api | 9.8 (v3.1) | Critical |
| CVE-2023-34659 | JeecgBoot 3.5.0 - SQL Injection | jeecg boot | 9.8 (v3.1) | Critical |
| CVE-2023-37629 | Online Piggery Management System v1.0 - Unauthenticated File Upload | simple online piggery management system | 9.8 (v3.1) | Critical |
| CVE-2024-30502 | WP Travel Engine <= 5.7.9 - SQL Injection | wp travel engine | 9.8 (v3.1) | Critical |
| CVE-2025-2776 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 9.8 (v3.1) | Critical |
| CVE-2025-2777 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 9.8 (v3.1) | Critical |
| CVE-2025-31324 | SAP NetWeaver Visual Composer Metadata Uploader - Deserialization | netweaver | 9.8 (v3.1) | Critical |
| CVE-2018-1821 | IBM Operational Decision Manager 8.x - XML External Entity Injection | operational decision manager | 9.1 (v3.0) | Critical |
| CVE-2018-20525 | Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal | roxy fileman | 9.1 (v3.1) | Critical |
| CVE-2021-37425 | Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) | mobiletogether server | 9.1 (v3.1) | Critical |
| CVE-2025-48703 | CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution | webpanel | 9.0 (v3.1) | Critical |
| CVE-2013-4863 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.8 (v3.1) | High |
| CVE-2017-11398 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.8 (v3.0) | High |
| CVE-2018-1213 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 8.8 (v3.0) | High |
| CVE-2018-7357 | ZTE ZXHN H168N - Improper Access Restrictions | zxhn h168n firmware | 8.8 (v3.0) | High |
| CVE-2018-7358 | ZTE ZXHN H168N - Improper Access Restrictions | zxhn h168n firmware | 8.8 (v3.0) | High |
| CVE-2022-28080 | Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated) | event management system | 8.8 (v3.1) | High |
| CVE-2022-46552 | D-Link DIR-846 - Remote Command Execution (RCE) vulnerability | dir-846 firmware | 8.8 (v3.1) | High |
| CVE-2023-32749 | Pydio Cells 4.1.2 - Unauthorised Role Assignments | cells | 8.8 (v3.1) | High |
| CVE-2023-49230 | Peplink Balance Two before 8.4.0 - Unauthenticated Config Upload | balance two firmware | 8.8 (v3.1) | High |
| CVE-2023-50071 | CVE-2023-50071 - Multiple SQL Injection | customer support system | 8.8 (v3.1) | High |
| CVE-2023-50094 | reNgine 2.2.0 - Command Injection | rengine | 8.8 (v3.1) | High |
| CVE-2024-24809 | Traccar - Unrestricted File Upload | traccar | 8.5 (v3.1) | High |
| CVE-2023-47218 | QNAP QTS and QuTS Hero - OS Command Injection | qts | 8.3 (v3.1) | High |
| CVE-2026-69101 | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | tis | 8.3 (v4.0) | High |
| CVE-2013-4862 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.1 (v3.1) | High |
| CVE-2017-14095 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.1 (v3.0) | High |
| CVE-2019-3759 | RSA IG&L Aveksa 7.1.1 - Remote Code Execution | rsa identity governance and lifecycle | 8.1 (v3.1) | High |
| CVE-2015-4681 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 7.8 (v3.0) | High |
| CVE-2019-20499 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20500 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20501 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2016-3473 | Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection | business intelligence publisher | 7.7 (v3.0) | High |
| CVE-2017-7185 | Cesanta Mongoose OS - Use-After-Free | mongoose embedded web server library | 7.5 (v3.0) | High |
| CVE-2023-40211 | Post Grid <= 2.2.50 - Information Exposure via REST API | post grid combo | 7.5 (v3.1) | High |
| CVE-2024-38653 | Ivanti Avalanche SmartDeviceServer - XML External Entity | avalanche | 7.5 (v3.1) | High |
| CVE-2025-2775 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 7.5 (v3.1) | High |
| CVE-2023-42344 | OpenCMS - XML external entity (XXE) | opencms | 7.3 (v3.1) | High |
| CVE-2015-4027 | Acunetix WVS 10 - Local Privilege Escalation | web vulnerability scanner | 7.2 (v2.0) | High |
| CVE-2019-2616 | Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection | business intelligence publisher | 7.2 (v3.1) | High |
| CVE-2024-5082 | Nexus Repository 2 - Remote Code Execution | Nexus Repository | 7.1 (v4.0) | High |
| CVE-2015-4685 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 7.0 (v3.0) | High |
| CVE-2018-1203 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 6.7 (v3.0) | Medium |
| CVE-2018-1204 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 6.7 (v3.0) | Medium |
| CVE-2013-4861 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2013-4865 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2015-4682 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 6.5 (v3.0) | Medium |
| CVE-2015-4684 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 6.5 (v3.0) | Medium |
| CVE-2017-3548 | Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPE | peoplesoft enterprise peopletools | 6.5 (v3.0) | Medium |
| CVE-2018-7691 | Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2) | fortify software security center | 6.5 (v3.0) | Medium |
| CVE-2021-22145 | Elasticsearch 7.10.0-7.13.3 - Information Disclosure | elasticsearch | 6.5 (v3.1) | Medium |
| CVE-2023-27167 | Suprema BioStar 2 v2.8.16 - SQL Injection | biostar 2 | 6.5 (v3.1) | Medium |
| CVE-2026-12898 | All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write | all-in-one-wp-migration | 6.5 (v3.1) | Medium |
| CVE-2017-14096 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 6.1 (v3.0) | Medium |
| CVE-2017-9979 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 6.1 (v3.0) | Medium |
| CVE-2021-27695 | openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting | openmaint | 6.1 (v3.1) | Medium |
| CVE-2017-14955 | Check_MK 1.2.8p25 - Information Disclosure | checkmk | 5.9 (v3.1) | Medium |
| CVE-2021-29460 | Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS) | kirby | 5.4 (v3.1) | Medium |
| CVE-2022-0020 | Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS) | cortex xsoar | 5.4 (v3.1) | Medium |
| CVE-2022-34140 | Feehi CMS 2.1.1 - Remote Code Execution (Authenticated) | feehi cms | 5.4 (v3.1) | Medium |
| CVE-2022-41358 | Garage Management System 1.0 (categoriesName) - Stored XSS | garage management system | 5.4 (v3.1) | Medium |
| CVE-2017-9978 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 5.3 (v3.0) | Medium |
| CVE-2018-1186 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1187 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1188 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1189 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1201 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1202 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 330791
- Source revision: 2378
- Source revision date: 2012-06-15