Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
BID:51257
Info
Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
| Bugtraq ID: | 51257 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0392 CVE-2012-0393 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2012 12:00AM |
| Updated: | Mar 19 2015 09:33AM |
| Credit: | Bruce Phillips and Johannes Dahse |
| Vulnerable: |
VMWare vCenter Orchestrator 4.1 VMWare vCenter Orchestrator 4.0 Apache Software Foundation Struts 2.2.3 Apache Software Foundation Struts 2.2.1 1 Apache Software Foundation Struts 2.2 Apache Software Foundation Struts 2.1.8 .1 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.6 Apache Software Foundation Struts 2.1.5 Apache Software Foundation Struts 2.1.2 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1 Apache Software Foundation Struts 2.0.14 Apache Software Foundation Struts 2.0.12 Apache Software Foundation Struts 2.0.11 .2 Apache Software Foundation Struts 2.0.11 .1 Apache Software Foundation Struts 2.0.11 Apache Software Foundation Struts 2.0.10 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 Apache Software Foundation Struts 2.2.3.1 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.4 Apache Software Foundation Struts 2.1.3 Apache Software Foundation Struts 2.0.13 |
| Not Vulnerable: |
Apache Software Foundation Struts 2.3.1.1 |
Discussion
Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
Apache Struts is prone to an arbitrary file-overwrite vulnerability and a remote command execution vulnerability.
Successful exploits will allow attackers to overwrite arbitrary files on the affected computer and execute arbitrary commands with the privileges of the user running the affected application.
Versions prior to Apache Struts 2.3.1.1 is vulnerable; other versions may also be affected.
Apache Struts is prone to an arbitrary file-overwrite vulnerability and a remote command execution vulnerability.
Successful exploits will allow attackers to overwrite arbitrary files on the affected computer and execute arbitrary commands with the privileges of the user running the affected application.
Versions prior to Apache Struts 2.3.1.1 is vulnerable; other versions may also be affected.
Solution / Fix
Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache Struts Remote Command Execution and Arbitrary File Overwrite Vulnerabilities
References:
References:
- Multiple critical vulnerabilities in Apache Struts2 (Sec Consult)
- Struts Homepage (Apache Software Foundation)
- Apache Struts 2 Documentation S2-008 (Apache Software Foundation)