On this page
Atomicorp WAF Rule 340152
Rule Summary
- Rule ID: 340152
- Status: Active
- Alert message: Request Body Parsing Failed. %{REQBODY_ERROR_MSG}: check your application or client for errors, this is not a false positive.
- Observed CWEs: CWE-20 (2), CWE-22 (6), CWE-27 (1), CWE-74 (1), CWE-77 (1), CWE-78 (9), CWE-79 (13), CWE-89 (6), CWE-94 (3), CWE-98 (1), CWE-200 (6), CWE-209 (1), CWE-255 (2), CWE-264 (4), CWE-285 (1), CWE-287 (2), CWE-288 (1), CWE-306 (3), CWE-352 (2), CWE-362 (1), CWE-416 (1), CWE-434 (8), CWE-502 (1), CWE-534 (1), CWE-611 (10), CWE-732 (1), CWE-829 (1), CWE-862 (2), CWE-863 (2), CWE-917 (1), CWE-918 (1), CWE-1336 (1)
- Revision: 1
- Rule severity: Notice (5)
- Phase: 2 (request body)
- Rule action: deny
- HTTP status: 400
- Logging: log, auditlog
Description
This is not a triggered rule, but a rule that is triggered when a multi-part message can not be assembled correctly. Typically this is caused when a multipart/request-data parser or XML parser fails to properly parse a request payload, generally because of either a broken client or client library, or a broken or corrupt request.
This is not a false positive, it seemly means that your application or client is creating multi-part messages that can not be assembled, either by ModSecurity or by the application. Check your applicant or client for the cause of this error and ensure that multipart messages are being sent and generated correctly.
It is not recommended you disable this rule. Doing so will leave your system open to impedance mismatch attacks . It is possible, for example, that a payload that cannot be parsed by ModSecurity can be successfully parsed by a more tolerant parser operating in the application. Therefore an attack could be passed through without detection.
False Positives
There are no known False Positives for this rule.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-34040 | Zhiyuan OA - arbitrary file upload leading | Zhiyuan OA Web Application System | 10.0 (v4.0) | Critical |
| CVE-2025-23211 | Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE | recipes | 9.9 (v3.1) | Critical |
| CVE-2013-4864 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 9.8 (v3.1) | Critical |
| CVE-2015-4683 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 9.8 (v3.0) | Critical |
| CVE-2015-6018 | ZYXEL PMG5318-B20A - OS Command Injection | pmg5318-b20a firmware | 9.8 (v3.0) | Critical |
| CVE-2017-14094 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 (v3.0) | Critical |
| CVE-2017-14097 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 (v3.0) | Critical |
| CVE-2017-18001 | Trustwave SWG 11.8.0.27 - SSH Unauthorized Access | secure web gateway | 9.8 (v3.0) | Critical |
| CVE-2018-12463 | Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection | fortify software security center | 9.8 (v3.1) | Critical |
| CVE-2018-19276 | OpenMRS Platform < 2.24.0 - Insecure Object Deserialization | openmrs | 9.8 (v3.1) | Critical |
| CVE-2018-20526 | Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal | roxy fileman | 9.8 (v3.0) | Critical |
| CVE-2018-6530 | D-Link - Unauthenticated Remote Code Execution | dir-860l firmware | 9.8 (v3.1) | Critical |
| CVE-2018-7600 | Drupal - Remote Code Execution | drupal | 9.8 (v3.1) | Critical |
| CVE-2019-17506 | D-Link DIR-868L/817LW - Information Disclosure | dir-868l b1 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-21978 | VMware View Planner <4.6 SP1- Remote Code Execution | view planner | 9.8 (v3.1) | Critical |
| CVE-2021-22005 | VMware vCenter Server - Arbitrary File Upload | cloud foundation | 9.8 (v3.1) | Critical |
| CVE-2021-24212 | WooCommerce Help Scout - Arbitrary File Upload | help scout | 9.8 (v3.1) | Critical |
| CVE-2021-24499 | WordPress Workreap - Remote Code Execution | workreap | 9.8 (v3.1) | Critical |
| CVE-2021-31805 | Apache Struts2 S2-062 - Remote Code Execution | struts | 9.8 (v3.1) | Critical |
| CVE-2021-3378 | FortiLogger 4.4.2.2 - Arbitrary File Upload | fortilogger | 9.8 (v3.1) | Critical |
| CVE-2022-31056 | GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration) | glpi | 9.8 (v3.1) | Critical |
| CVE-2023-2648 | Weaver E-Office 9.5 - Remote Code Execution | e-office | 9.8 (v3.1) | Critical |
| CVE-2023-2734 | MStore API <= 3.9.1 - Authentication Bypass | mstore api | 9.8 (v3.1) | Critical |
| CVE-2023-34659 | JeecgBoot 3.5.0 - SQL Injection | jeecg boot | 9.8 (v3.1) | Critical |
| CVE-2024-30502 | WP Travel Engine <= 5.7.9 - SQL Injection | wp travel engine | 9.8 (v3.1) | Critical |
| CVE-2025-2776 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 9.8 (v3.1) | Critical |
| CVE-2025-2777 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 9.8 (v3.1) | Critical |
| CVE-2025-31324 | SAP NetWeaver Visual Composer Metadata Uploader - Deserialization | netweaver | 9.8 (v3.1) | Critical |
| CVE-2018-1821 | IBM Operational Decision Manager 8.x - XML External Entity Injection | operational decision manager | 9.1 (v3.0) | Critical |
| CVE-2018-20525 | Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal | roxy fileman | 9.1 (v3.1) | Critical |
| CVE-2021-37425 | Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) | mobiletogether server | 9.1 (v3.1) | Critical |
| CVE-2025-48703 | CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution | webpanel | 9.0 (v3.1) | Critical |
| CVE-2013-4863 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.8 (v3.1) | High |
| CVE-2017-11398 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.8 (v3.0) | High |
| CVE-2018-1213 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 8.8 (v3.0) | High |
| CVE-2018-7357 | ZTE ZXHN H168N - Improper Access Restrictions | zxhn h168n firmware | 8.8 (v3.0) | High |
| CVE-2018-7358 | ZTE ZXHN H168N - Improper Access Restrictions | zxhn h168n firmware | 8.8 (v3.0) | High |
| CVE-2022-28080 | Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated) | event management system | 8.8 (v3.1) | High |
| CVE-2022-46552 | D-Link DIR-846 - Remote Command Execution (RCE) vulnerability | dir-846 firmware | 8.8 (v3.1) | High |
| CVE-2023-32749 | Pydio Cells 4.1.2 - Unauthorised Role Assignments | cells | 8.8 (v3.1) | High |
| CVE-2023-49230 | Peplink Balance Two before 8.4.0 - Unauthenticated Config Upload | balance two firmware | 8.8 (v3.1) | High |
| CVE-2023-50071 | CVE-2023-50071 - Multiple SQL Injection | customer support system | 8.8 (v3.1) | High |
| CVE-2023-50094 | reNgine 2.2.0 - Command Injection | rengine | 8.8 (v3.1) | High |
| CVE-2024-24809 | Traccar - Unrestricted File Upload | traccar | 8.5 (v3.1) | High |
| CVE-2023-47218 | QNAP QTS and QuTS Hero - OS Command Injection | qts | 8.3 (v3.1) | High |
| CVE-2026-69101 | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | tis | 8.3 (v4.0) | High |
| CVE-2013-4862 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.1 (v3.1) | High |
| CVE-2017-14095 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.1 (v3.0) | High |
| CVE-2019-3759 | RSA IG&L Aveksa 7.1.1 - Remote Code Execution | rsa identity governance and lifecycle | 8.1 (v3.1) | High |
| CVE-2015-4681 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 7.8 (v3.0) | High |
| CVE-2019-20499 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20500 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20501 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2016-3473 | Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection | business intelligence publisher | 7.7 (v3.0) | High |
| CVE-2017-7185 | Cesanta Mongoose OS - Use-After-Free | mongoose embedded web server library | 7.5 (v3.0) | High |
| CVE-2023-40211 | Post Grid <= 2.2.50 - Information Exposure via REST API | post grid combo | 7.5 (v3.1) | High |
| CVE-2024-38653 | Ivanti Avalanche SmartDeviceServer - XML External Entity | avalanche | 7.5 (v3.1) | High |
| CVE-2025-2775 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 7.5 (v3.1) | High |
| CVE-2023-42344 | OpenCMS - XML external entity (XXE) | opencms | 7.3 (v3.1) | High |
| CVE-2015-4027 | Acunetix WVS 10 - Local Privilege Escalation | web vulnerability scanner | 7.2 (v2.0) | High |
| CVE-2019-2616 | Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection | business intelligence publisher | 7.2 (v3.1) | High |
| CVE-2024-5082 | Nexus Repository 2 - Remote Code Execution | Nexus Repository | 7.1 (v4.0) | High |
| CVE-2015-4685 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 7.0 (v3.0) | High |
| CVE-2018-1203 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 6.7 (v3.0) | Medium |
| CVE-2018-1204 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | 6.7 (v3.0) | Medium |
| CVE-2013-4861 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2013-4865 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2015-4682 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 6.5 (v3.0) | Medium |
| CVE-2015-4684 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 6.5 (v3.0) | Medium |
| CVE-2017-3548 | Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPE | peoplesoft enterprise peopletools | 6.5 (v3.0) | Medium |
| CVE-2018-7691 | Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2) | fortify software security center | 6.5 (v3.0) | Medium |
| CVE-2021-22145 | Elasticsearch 7.10.0-7.13.3 - Information Disclosure | elasticsearch | 6.5 (v3.1) | Medium |
| CVE-2023-27167 | Suprema BioStar 2 v2.8.16 - SQL Injection | biostar 2 | 6.5 (v3.1) | Medium |
| CVE-2026-12898 | All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write | all-in-one-wp-migration | 6.5 (v3.1) | Medium |
| CVE-2017-14096 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 6.1 (v3.0) | Medium |
| CVE-2017-9979 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 6.1 (v3.0) | Medium |
| CVE-2021-27695 | openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting | openmaint | 6.1 (v3.1) | Medium |
| CVE-2017-14955 | Check_MK 1.2.8p25 - Information Disclosure | checkmk | 5.9 (v3.1) | Medium |
| CVE-2021-29460 | Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS) | kirby | 5.4 (v3.1) | Medium |
| CVE-2022-0020 | Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS) | cortex xsoar | 5.4 (v3.1) | Medium |
| CVE-2022-34140 | Feehi CMS 2.1.1 - Remote Code Execution (Authenticated) | feehi cms | 5.4 (v3.1) | Medium |
| CVE-2022-41358 | Garage Management System 1.0 (categoriesName) - Stored XSS | garage management system | 5.4 (v3.1) | Medium |
| CVE-2017-9978 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 5.3 (v3.0) | Medium |
| CVE-2018-1186 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1187 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1188 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1189 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1201 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
| CVE-2018-1202 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon | 4.8 (v3.0) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 340152
- Source revision: 2310
- Source revision date: 2012-05-07