Apache Struts CVE-2014-7809 Security Bypass Vulnerability
BID:71548
Info
Apache Struts CVE-2014-7809 Security Bypass Vulnerability
| Bugtraq ID: | 71548 |
| Class: | Design Error |
| CVE: |
CVE-2014-7809 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2014 12:00AM |
| Updated: | Oct 26 2016 01:14AM |
| Credit: | Philippe Arteau of Groupe Technologies Desjardins |
| Vulnerable: |
Oracle WebCenter Sites 11.1.1 8.0 Oracle WebCenter Sites 12.2.1.0 Oracle WebCenter Sites 11.1.1.6.1 Oracle MySQL Enterprise Monitor 3.0.18 Oracle MySQL Enterprise Monitor 3.0.10 Oracle MySQL Enterprise Monitor 3.0.9 Oracle MySQL Enterprise Monitor 3.0.8 Oracle MySQL Enterprise Monitor 3.0 Oracle MySQL Enterprise Monitor 2.3.19 Oracle MySQL Enterprise Monitor 2.3.16 Oracle MySQL Enterprise Monitor 2.3.15 Oracle MySQL Enterprise Monitor 2.3.14 Oracle MySQL Enterprise Monitor 2.3.13 Oracle MySQL Enterprise Monitor 3.0.4 Oracle MySQL Enterprise Monitor 2.3 Oracle FLEXCUBE Private Banking 12.1 Oracle FLEXCUBE Private Banking 12.0.3 Oracle FLEXCUBE Private Banking 12.0.1 Oracle FLEXCUBE Private Banking 2.2 Oracle FLEXCUBE Private Banking 2.0.1 Oracle FLEXCUBE Private Banking 2.0 IBM FlashSystem V840 9848-AC1 IBM FlashSystem V840 9848-AC0 IBM FlashSystem V840 9846-AC1 IBM FlashSystem V840 9846-AC0 IBM FlashSystem 840 9848-AE1 IBM FlashSystem 840 9846-AE1 IBM FlashSystem 840 9843-AE1 IBM FlashSystem 840 9840-AE1 Apache Struts 2.3.4 1 Apache Struts 2.3.4 Apache Struts 2.2.3 Apache Struts 2.2.1 1 Apache Struts 2.2 Apache Struts 2.1.8 .1 Apache Struts 2.1.8 Apache Struts 2.1.6 Apache Struts 2.1.5 Apache Struts 2.1.2 Apache Struts 2.1.1 Apache Struts 2.1 Apache Struts 2.0.14 Apache Struts 2.0.12 Apache Struts 2.0.11 .2 Apache Struts 2.0.11 .1 Apache Struts 2.0.11 Apache Struts 2.0.10 Apache Struts 2.0.9 Apache Struts 2.0.8 Apache Struts 2.0.7 Apache Struts 2.0.6 Apache Struts 2.0.5 Apache Struts 2.0.4 Apache Struts 2.0.3 Apache Struts 2.0.2 Apache Struts 2.0.1 Apache Struts 2.0 Apache Struts 2.3.8 Apache Struts 2.3.7 Apache Struts 2.3.3 Apache Struts 2.3.16.3 Apache Struts 2.3.16.2 Apache Struts 2.3.16.1 Apache Struts 2.3.16 Apache Struts 2.3.15.3 Apache Struts 2.3.15.2 Apache Struts 2.3.15.1 Apache Struts 2.3.15 Apache Struts 2.3.14.3 Apache Struts 2.3.14.2 Apache Struts 2.3.14.1 Apache Struts 2.3.14 Apache Struts 2.3.12 Apache Struts 2.3.1.2 Apache Struts 2.3.1.1 Apache Struts 2.3.1 Apache Struts 2.2.3.1 Apache Struts 2.1.4 Apache Struts 2.1.3 Apache Struts 2.0.13 |
| Not Vulnerable: |
Apache Struts 2.3.20 |
Discussion
Apache Struts CVE-2014-7809 Security Bypass Vulnerability
Apache Struts is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
An attacker can exploit this issue to bypass cross-site request forgery protections and perform unauthorized actions. This may lead to further attacks.
Apache Struts versions 2.0.0 through 2.3.16.3 are vulnerable.
Apache Struts is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
An attacker can exploit this issue to bypass cross-site request forgery protections and perform unauthorized actions. This may lead to further attacks.
Apache Struts versions 2.0.0 through 2.3.16.3 are vulnerable.
Exploit / POC
Apache Struts CVE-2014-7809 Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Apache Struts CVE-2014-7809 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Struts CVE-2014-7809 Security Bypass Vulnerability
References:
References:
- Generated value of token can be predictable (The Apache Software Foundation)
- Struts Homepage (Apache Software Foundation)
- Critical Patch Security Advisory - October 2016 (Oracle)
- Oracle Critical Patch Update Advisory - April 2015 (Oracle)
- Oracle Critical Patch Update Advisory - July 2015 (Oracle)
- Security Bulletin: IBM FlashSystem 840 and IBM FlashSystem V840, -AE1 models nod (IBM)
- Security Bulletin: The IBM FlashSystem V840 product model numbers AC0 and AC1 no (IBM)