Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
BID:67064
Info
Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
| Bugtraq ID: | 67064 |
| Class: | Design Error |
| CVE: |
CVE-2014-0112 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2014 12:00AM |
| Updated: | Apr 16 2015 06:14PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Apache Software Foundation Struts 2.2.3 Apache Software Foundation Struts 2.2 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.6 Apache Software Foundation Struts 2.1.5 Apache Software Foundation Struts 2.1.2 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1 Apache Software Foundation Struts 2.0.14 Apache Software Foundation Struts 2.0.12 Apache Software Foundation Struts 2.0.11 Apache Software Foundation Struts 2.0.10 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 Apache Software Foundation Struts 2.3.1.2 Apache Software Foundation Struts 2.3.1.1 Apache Software Foundation Struts 2.2.3.1 Apache Software Foundation Struts 2.1.4 Apache Software Foundation Struts 2.1.3 Apache Software Foundation Struts 2.0.13 |
| Not Vulnerable: | |
Discussion
Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
Apache Struts is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Apache Struts versions 2.0.0 through 2.3.16.1 are vulnerable.
Note: This issue exists due to an incomplete fix for CVE-2014-0094 (identified in BID 65999- Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability).
Apache Struts is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Apache Struts versions 2.0.0 through 2.3.16.1 are vulnerable.
Note: This issue exists due to an incomplete fix for CVE-2014-0094 (identified in BID 65999- Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability).
Exploit / POC
Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
The following exploit is available:
Attackers can use readily available tools to exploit this issue.
The following exploit is available:
Solution / Fix
Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Struts ClassLoader Manipulation Incomplete Fix Security Bypass Vulnerability
References:
References:
- Struts Homepage (Apache Software Foundation)