The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Struts | apache-struts-upgrade-latest | Mar 9, 2017 | Mar 9, 2017 | |
| Oracle Weblogic | oracle-weblogic-jul-2017-cpu-10_3_6_0_0oracle-weblogic-jul-2017-cpu-12_1_3_0_0oracle-weblogic-jul-2017-cpu-12_2_1_1_0oracle-weblogic-jul-2017-cpu-12_2_1_2_0 | Apr 3, 2018 | Mar 10, 2017 | |
| Struts | apache-struts-upgrade-2_3_32apache-struts-upgrade-2_5_10_1 | Jun 27, 2017 | Mar 10, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub