Apache Struts CVE-2013-4310 Security Bypass Vulnerability
BID:62584
Info
Apache Struts CVE-2013-4310 Security Bypass Vulnerability
| Bugtraq ID: | 62584 |
| Class: | Unknown |
| CVE: |
CVE-2013-4310 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2013 12:00AM |
| Updated: | Apr 13 2015 09:25PM |
| Credit: | Zhangyan (L) of Huawei PSIRT |
| Vulnerable: |
Oracle MySQL Enterprise Monitor 2.3.14 Oracle MySQL Enterprise Monitor 2.3.13 Oracle MySQL Enterprise Monitor 2.3 IBM Storwize V7000 Unified 1.4 1 IBM Storwize V7000 Unified 1.4 0 IBM Storwize V7000 Unified 1.3.2 3 IBM Storwize V7000 Unified 1.3.2 1 IBM Storwize V7000 Unified 1.3.2 0 IBM Storwize V7000 Unified 1.4.2.0 IBM Storwize V7000 Unified 1.4.1.1 IBM Storwize V7000 Unified 1.4.1.0 IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 IBM Storwize V7000 7.1.0.5 IBM Storwize V5000 7.1 IBM Storwize V3700 7.1 IBM Storwize V3500 7.1 IBM Sterling Web Channel 9.1 IBM Sterling Web Channel 9.0 IBM Sterling Selling and Fulfillment Foundation 9.2.1 IBM Sterling Selling and Fulfillment Foundation 9.2 IBM Sterling Selling and Fulfillment Foundation 9.1 IBM Sterling Selling and Fulfillment Foundation 9.0 IBM Sterling Order Management 8.5 IBM Sterling Field Sales 9.2.1 IBM Sterling Field Sales 9.2.0 IBM Sterling Field Sales 9.1.0 IBM Sterling Field Sales 9.0 IBM SAN Volume Controller 7.1.0.5 IBM Platform Symphony 6.1.1 IBM Platform Symphony 6.1 IBM Platform Symphony 5.2 IBM Platform HPC 4.1.1 IBM Platform HPC 3.2 IBM Platform Cluster Manager- Standard Edition 4.1 IBM Platform Cluster Manager- Standard Edition 3.2 IBM Platform Cluster Manager- Advanced Edition 4.1 IBM Platform Cluster Manager- Advanced Edition 3.2 IBM Platform Application Center 9.1.1 IBM Platform Application Center 9.1 IBM Platform Application Center 8.3 IBM Flex System V7000 7.1 IBM Connections 4.5 IBM Connections 4.0 IBM Connections 3.0.1.1 IBM Connections 3.0.1 Apache Struts 2 0 Apache Struts 2.3.4 1 Apache Struts 2.3.4 Apache Struts 2.2.3 Apache Struts 2.2.1 1 Apache Struts 2.2 Apache Struts 2.1.8 .1 Apache Struts 2.1.8 Apache Struts 2.1.6 Apache Struts 2.1.5 Apache Struts 2.1.2 Apache Struts 2.1.1 Apache Struts 2.1.1 Apache Struts 2.1 Apache Struts 2.0.14 Apache Struts 2.0.12 Apache Struts 2.0.11 .2 Apache Struts 2.0.11 .1 Apache Struts 2.0.11 Apache Struts 2.0.10 Apache Struts 2.0.9 Apache Struts 2.0.8 Apache Struts 2.0.7 Apache Struts 2.0.6 Apache Struts 2.0.5 Apache Struts 2.0.4 Apache Struts 2.0.3 Apache Struts 2.0.2 Apache Struts 2.0.1 Apache Struts 2.0 Apache Struts 2.3.15.2 Apache Struts 2.3.15.1 Apache Struts 2.3.15 Apache Struts 2.3.14.3 Apache Struts 2.3.14.2 Apache Struts 2.3.14.1 Apache Struts 2.3.14 Apache Struts 2.3.1.2 Apache Struts 2.3.1.1 Apache Struts 2.2.3.1 Apache Struts 2.1.8 Apache Struts 2.1.4 Apache Struts 2.1.3 Apache Struts 2.0.13 |
| Not Vulnerable: |
IBM Storwize V7000 Unified 1.4.2.1 IBM Storwize V7000 7.1.0.6 IBM Storwize V5000 7.1.0.6 IBM Storwize V3700 7.1.0.6 IBM Storwize V3500 7.1.0.6 IBM SAN Volume Controller 7.1.0.6 IBM Flex System V7000 7.1.0.6 Apache Struts 2.3.15.3 |
Discussion
Apache Struts CVE-2013-4310 Security Bypass Vulnerability
Apache Struts is prone to a security-bypass vulnerability.
Few technical details are currently available. This BID will be updated as more information emerges.
Successful exploits will allow an attacker to bypass certain security restrictions which may lead to further attacks.
Versions prior to Apache Struts 2.3.15.3 are vulnerable.
Note: The fix implemented in Apache Struts 2.3.15.2 was incomplete.
Apache Struts is prone to a security-bypass vulnerability.
Few technical details are currently available. This BID will be updated as more information emerges.
Successful exploits will allow an attacker to bypass certain security restrictions which may lead to further attacks.
Versions prior to Apache Struts 2.3.15.3 are vulnerable.
Note: The fix implemented in Apache Struts 2.3.15.2 was incomplete.
Exploit / POC
Apache Struts CVE-2013-4310 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Struts CVE-2013-4310 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Struts CVE-2013-4310 Security Bypass Vulnerability
References:
References:
- Broken Access Control Vulnerability in Apache Struts2 (Apache Software Foundation)
- Oracle Critical Patch Update Advisory - January 2014 (Oracle)
- Security Bulletin: IBM Platform Cluster Manager 13 Advanced Edition (CVE-2013-2 (IBM)
- Security Bulletin: IBM Platform Cluster Manager 13 Standard Edition (CVE-2013-2 (IBM)
- Security Bulletin: IBM Platform HPC (CVE-2013-2251 CVE-2013-2248 CVE-2013-2135 C (IBM)
- Struts Homepage (Apache Software Foundation)
- Text Form of Oracle Critical Patch Update - January 2014 Risk Matrices (Oracle)
- Version Notes 2.3.15.2 (Apache Software Foundation)
- Version Notes 2.3.15.3 (Apache Software Foundation)
- IBM Sterling Order Management and IBM Sterling Configure, Price, Quote are affec (IBM)
- Oracle Critical Patch Update Pre-Release Announcement - January 2014 (Oracle)
- Security Bulletin: IBM Connections Security Refresh (CVE-2013-4316 CVE-2013-4310 (IBM)
- Security Bulletin: IBM Platform Application Center (CVE-2013-2251 CVE-2013-2248 (IBM)
- Security Bulletin: IBM Platform Symphony (CVE-2013-2251 CVE-2013-2248 CVE-2013-2 (IBM)
- Security Bulletin: IBM Storwize V7000 Unified V1.4.2.1 Includes Fixes for IBM St (IBM)
- Security Bulletin: Unauthorized access exposure on IBM SAN Volume Controller and (IBM)
- Security Bulletin:Sterling Web Channel is affected by Apache Struts 2 security v (IBM)