Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
BID:60345
Info
Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
| Bugtraq ID: | 60345 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2135 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2013 12:00AM |
| Updated: | Mar 19 2015 08:49AM |
| Credit: | Jon Passki via Coverity Security Research Laboratory |
| Vulnerable: |
IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 Apache Software Foundation Struts 2.2.3 Apache Software Foundation Struts 2.2.1 1 Apache Software Foundation Struts 2.2 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.6 Apache Software Foundation Struts 2.1.5 Apache Software Foundation Struts 2.1.2 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1 Apache Software Foundation Struts 2.0.14 Apache Software Foundation Struts 2.0.12 Apache Software Foundation Struts 2.0.11 Apache Software Foundation Struts 2.0.10 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 Apache Software Foundation Struts 2.3.1.2 Apache Software Foundation Struts 2.3.1.1 Apache Software Foundation Struts 2.2.3.1 Apache Software Foundation Struts 2.1.4 Apache Software Foundation Struts 2.1.3 Apache Software Foundation Struts 2.0.13 |
| Not Vulnerable: | |
Exploit / POC
Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
The following example URIs are available:
http://www.example.com/example/%24%7B%23foo%3D%27Menu%27%2C%23foo%7D
http://www.example.com/example/${#foo='Menu',#foo}
The following example URIs are available:
http://www.example.com/example/%24%7B%23foo%3D%27Menu%27%2C%23foo%7D
http://www.example.com/example/${#foo='Menu',#foo}
Solution / Fix
Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Struts CVE-2013-2135 OGNL Expression Injection Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Apache Struts 2 Documentation S2-015 (Apache Software Foundation)
- Security Bulletin: IBM Platform Cluster Manager 13 Advanced Edition (CVE-2013-2 (IBM)
- Security Bulletin: IBM Platform Cluster Manager 13 Standard Edition (CVE-2013-2 (IBM)
- Security Bulletin: IBM Platform HPC (CVE-2013-2251 CVE-2013-2248 CVE-2013-2135 C (IBM)
- Struts 2 Remote Code Execution via OGNL Double Evaluation ( Jon Passki)
- Struts Homepage (Apache Software Foundation)
- Version Notes 2.3.14.3 (Apache Software Foundation)
- IBM Sterling Order Management and IBM Sterling Configure, Price, Quote are affec (IBM)
- Oracle Critical Patch Update Pre-Release Announcement - January 2014 (Oracle)
- Security Advisory-Multiple Apache Struts 2 Vulnerabilities in Huawei Products (Huawei Technologies)
- Security Bulletin: IBM Connections Security Refresh (CVE-2013-4316 CVE-2013-4310 (IBM)
- Security Bulletin: IBM Platform Application Center (CVE-2013-2251 CVE-2013-2248 (IBM)
- Security Bulletin: IBM Platform Symphony (CVE-2013-2251 CVE-2013-2248 CVE-2013-2 (IBM)
- Security Bulletin: IBM Storwize V7000 Unified Update Includes Fixes for Multiple (IBM)
- Security Bulletin:Sterling Web Channel is affected by Apache Struts 2 security v (IBM)
- Unauthorized access exposure on IBM SAN Volume Controller and Storwize Family (C (IBM)