The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Struts | — | Upgrade to the latest version of Apache Struts | Mar 9, 2017 | Mar 9, 2017 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 25871788 for version 12.2.1.2.0.Apply the Patch Set Update (PSU) 25869650 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 25869659 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 25961827 for version 12.2.1.1.0. | Apr 3, 2018 | Mar 10, 2017 |
| Struts | — | Upgrade to Apache Struts version 2.5.10.1Upgrade to Apache Struts version 2.3.32 | Jun 27, 2017 | Mar 11, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub