Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
BID:60346
Info
Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
| Bugtraq ID: | 60346 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2134 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2013 12:00AM |
| Updated: | Mar 19 2015 09:46AM |
| Credit: | Jon Passki via Coverity Security Research Laboratory |
| Vulnerable: |
IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 Gentoo Linux Apache Software Foundation Struts 2.2.3 Apache Software Foundation Struts 2.2.1 1 Apache Software Foundation Struts 2.2 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.6 Apache Software Foundation Struts 2.1.5 Apache Software Foundation Struts 2.1.2 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1 Apache Software Foundation Struts 2.0.14 Apache Software Foundation Struts 2.0.12 Apache Software Foundation Struts 2.0.11 Apache Software Foundation Struts 2.0.10 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 Apache Software Foundation Struts 2.3.1.2 Apache Software Foundation Struts 2.3.1.1 Apache Software Foundation Struts 2.2.3.1 Apache Software Foundation Struts 2.1.4 Apache Software Foundation Struts 2.1.3 Apache Software Foundation Struts 2.0.13 |
| Not Vulnerable: | |
Discussion
Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
Apache Struts is prone to a remote OGNL expression injection vulnerability.
Successfully exploiting this issue may allow an attacker to manipulate server-side objects and execute arbitrary commands within the context of the application.
Apache Struts 2.0.0 through versions 2.3.14.3 are vulnerable.
Apache Struts is prone to a remote OGNL expression injection vulnerability.
Successfully exploiting this issue may allow an attacker to manipulate server-side objects and execute arbitrary commands within the context of the application.
Apache Struts 2.0.0 through versions 2.3.14.3 are vulnerable.
Solution / Fix
Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Struts CVE-2013-2134 OGNL Expression Injection Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Struts Homepage (Apache Software Foundation)