Apache Struts CVE-2018-11776 Remote Code Execution Vulnerability
BID:105125
CVE-2018-11776 |Info
Apache Struts CVE-2018-11776 Remote Code Execution Vulnerability
| Bugtraq ID: | 105125 |
| Class: | Unknown |
| CVE: |
CVE-2018-11776 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2018 12:00AM |
| Updated: | Jan 16 2019 09:00AM |
| Credit: | Man Yue Mo from the Semmle Security Research team |
| Vulnerable: |
Oracle MySQL Enterprise Monitor 3.2.1182 Oracle MySQL Enterprise Monitor 3.0.22 Oracle MySQL Enterprise Monitor 3.0.20 Oracle MySQL Enterprise Monitor 3.0.18 Oracle MySQL Enterprise Monitor 3.0.10 Oracle MySQL Enterprise Monitor 3.0.9 Oracle MySQL Enterprise Monitor 3.0.8 Oracle MySQL Enterprise Monitor 3.0 Oracle MySQL Enterprise Monitor 2.3.20 Oracle MySQL Enterprise Monitor 2.3.19 Oracle MySQL Enterprise Monitor 2.3.16 Oracle MySQL Enterprise Monitor 2.3.15 Oracle MySQL Enterprise Monitor 2.3.14 Oracle MySQL Enterprise Monitor 2.3.13 Oracle MySQL Enterprise Monitor 8.0.2.8191 Oracle MySQL Enterprise Monitor 8.0.0.8131 Oracle MySQL Enterprise Monitor 4.0.6.5281 Oracle MySQL Enterprise Monitor 4.0.4.5235 Oracle MySQL Enterprise Monitor 4.0.2.5168 Oracle MySQL Enterprise Monitor 4.0.0.5135 Oracle MySQL Enterprise Monitor 3.4.9.4237 Oracle MySQL Enterprise Monitor 3.4.7.4297 Oracle MySQL Enterprise Monitor 3.4.5.4248 Oracle MySQL Enterprise Monitor 3.4.4.4226 Oracle MySQL Enterprise Monitor 3.4.2.4181 Oracle MySQL Enterprise Monitor 3.4.1 Oracle MySQL Enterprise Monitor 3.4.0 Oracle MySQL Enterprise Monitor 3.3.7.3306 Oracle MySQL Enterprise Monitor 3.3.6.3293 Oracle MySQL Enterprise Monitor 3.3.4.3247 Oracle MySQL Enterprise Monitor 3.3.3.1199 Oracle MySQL Enterprise Monitor 3.3.2.1162 Oracle MySQL Enterprise Monitor 3.3.0.1098 Oracle MySQL Enterprise Monitor 3.2.8.2223 Oracle MySQL Enterprise Monitor 3.2.7.1204 Oracle MySQL Enterprise Monitor 3.2.5.1141 Oracle MySQL Enterprise Monitor 3.2.4.1102 Oracle MySQL Enterprise Monitor 3.2.1.1049 Oracle MySQL Enterprise Monitor 3.1.6.8003 Oracle MySQL Enterprise Monitor 3.1.5.7958 Oracle MySQL Enterprise Monitor 3.1.4.7895 Oracle MySQL Enterprise Monitor 3.1.3.7856 Oracle MySQL Enterprise Monitor 3.1.2 Oracle MySQL Enterprise Monitor 3.0.4 Oracle MySQL Enterprise Monitor 3.0.25 Oracle MySQL Enterprise Monitor 3.0 Oracle MySQL Enterprise Monitor 2.3 Oracle Communications Policy Management 12.1.1 Oracle Communications Policy Management 12.1 Oracle Communications Policy Management 11.5 Oracle Communications Policy Management 10.5 Oracle Communications Policy Management 10.4.1 Oracle Communications Policy Management 9.9.2 Oracle Communications Policy Management 9.9.1 Oracle Communications Policy Management 9.9 Oracle Communications Policy Management 9.7.3 Oracle Communications Policy Management 12.2 Oracle Communications Policy Management 12.0 Oracle Communications Policy Management 11.5 Cisco Unified SIP Proxy Software 0 Cisco Hosted Collaboration Solution for Contact Center 11.6(1) Cisco Hosted Collaboration Solution for Contact Center 11.5(1) Cisco Hosted Collaboration Solution for Contact Center 11.0(1) Cisco Hosted Collaboration Solution for Contact Center 10.5(1) Apache Struts 2.5.16 Apache Struts 2.5.14 Apache Struts 2.3.31 Apache Struts 2.3.30 Apache Struts 2.3.28 Apache Struts 2.3.24 Apache Struts 2.3.5 Apache Struts 2.3.4 1 Apache Struts 2.3.4 Apache Struts 2.5.9 Apache Struts 2.5.8 Apache Struts 2.5.7 Apache Struts 2.5.6 Apache Struts 2.5.5 Apache Struts 2.5.4 Apache Struts 2.5.3 Apache Struts 2.5.2 Apache Struts 2.5.14.1 Apache Struts 2.5.13 Apache Struts 2.5.12 Apache Struts 2.5.11 Apache Struts 2.5.10.1 Apache Struts 2.5.10 Apache Struts 2.5.1 Apache Struts 2.3.8 Apache Struts 2.3.7 Apache Struts 2.3.34 Apache Struts 2.3.33 Apache Struts 2.3.32 Apache Struts 2.3.29 Apache Struts 2.3.28.1 Apache Struts 2.3.24.3 Apache Struts 2.3.24.2 Apache Struts 2.3.24.1 Apache Struts 2.3.20.3 Apache Struts 2.3.20.2 Apache Struts 2.3.20.1 Apache Struts 2.3.20 Apache Struts 2.3.16.3 Apache Struts 2.3.16.2 Apache Struts 2.3.16.1 Apache Struts 2.3.16 Apache Struts 2.3.15.3 Apache Struts 2.3.15.2 Apache Struts 2.3.15.1 Apache Struts 2.3.15 Apache Struts 2.3.14.3 Apache Struts 2.3.14.2 Apache Struts 2.3.14.1 Apache Struts 2.3.14 Apache Struts 2.3.1.2 Apache Struts 2.3.1.1 Apache Struts 2.3.1 |
| Not Vulnerable: |
Oracle Communications Policy Management 12.5 Apache Struts 2.5.17 Apache Struts 2.3.35 |
Discussion
Apache Struts CVE-2018-11776 Remote Code Execution Vulnerability
Apache Struts is prone to a remote code-execution vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploit attempts may cause a denial-of-service condition.
Apache Struts 2.3 through 2.3.34, and 2.5 through Struts 2.5.16 are vulnerable.
Apache Struts is prone to a remote code-execution vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploit attempts may cause a denial-of-service condition.
Apache Struts 2.3 through 2.3.34, and 2.5 through Struts 2.5.16 are vulnerable.
Exploit / POC
Apache Struts CVE-2018-11776 Remote Code Execution Vulnerability
Reports indicate that this issue is being exploited in the wild. Please see the references for more information.
Reports indicate that this issue is being exploited in the wild. Please see the references for more information.
Solution / Fix
Apache Struts CVE-2018-11776 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Struts CVE-2018-11776 Remote Code Execution Vulnerability
References:
References:
- Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1) (Mazin Ahmed)
- APACHE STRUTS VULNERABILITY CVE-2018-11776 (Larry Cashdollar)
- Bug 1620019 - (CVE-2018-11776) CVE-2018-11776 struts2: Using specific results an (Red Hat Bugzilla)
- CVE-2018-11776 (Red Hat Bugzilla)
- St2-057 (jas502n)
- Struts Homepage (Apache Software Foundation)
- cisco-sa-20180823-apache-struts: Apache Struts Remote Code Execution Vulnerabil (Cisco)
- Oracle Critical Patch Update Advisory - January 2019 (Oracle)
- Oracle Critical Patch Update Advisory - October 2018 (Oracle)
- S2-057 (Apache)