Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
BID:49728
Info
Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
| Bugtraq ID: | 49728 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0838 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2011 12:00AM |
| Updated: | Mar 19 2015 09:39AM |
| Credit: | Hideyuki Suzumi |
| Vulnerable: |
Apache Software Foundation Struts 2.2.3 Apache Software Foundation Struts 2.2.1 1 Apache Software Foundation Struts 2.2 Apache Software Foundation Struts 2.1.8 .1 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.6 Apache Software Foundation Struts 2.1.5 Apache Software Foundation Struts 2.1.2 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1 Apache Software Foundation Struts 2.0.14 Apache Software Foundation Struts 2.0.12 Apache Software Foundation Struts 2.0.11 .2 Apache Software Foundation Struts 2.0.11 .1 Apache Software Foundation Struts 2.0.11 Apache Software Foundation Struts 2.0.10 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.4 Apache Software Foundation Struts 2.1.3 Apache Software Foundation Struts 2.0.13 |
| Not Vulnerable: |
Apache Software Foundation Struts 2.2.3.1 |
Discussion
Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
Apache Struts is prone to a vulnerability that results in the evaluation of arbitrary user-supplied input.
Successful exploits will allow attackers to run arbitrary OGNL expressions in the context of the affected application. This may result in the disclosure of potentially sensitive information; other attacks are also possible.
Apache Struts is prone to a vulnerability that results in the evaluation of arbitrary user-supplied input.
Successful exploits will allow attackers to run arbitrary OGNL expressions in the context of the affected application. This may result in the disclosure of potentially sensitive information; other attacks are also possible.
Exploit / POC
Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
Attackers can use standard tools to exploit this issue.
Attackers can use standard tools to exploit this issue.
Solution / Fix
Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
References:
References:
- Struts Homepage (Apache Software Foundation)
- Vulnerability: User input is evaluated as an OGNL expression when there's a conv (Apache)