Release date:
Updated on: 2011-12-16
Affected Systems:
Apache Group Struts 2.1.8. 1
Apache Group Struts 2.0.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50940
Apache Struts is an open-source web application framework for developing Java Web applications.
Apache Struts has a Security Restriction Bypass Vulnerability. Successful attacks allow attackers to bypass the security restriction to obtain illegal access.
<* Source: Hisato Killing
Link: https://issues.apache.org/jira/browse/WW-2264
Https://issues.apache.org/jira/browse/WW-3631
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/SomeAction.action? Session. somekey = someValue
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://httpd.apache.org/