Release date:
Updated on:
Affected Systems:
Apache Group Struts 2.x
Unaffected system:
Apache Group Struts 2.3.1.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51257
Apache Struts is an open-source Web application framework for developing Java Web applications.
Apache Struts has the vulnerability of remote command execution and arbitrary file overwrite. After successful exploitation, attackers can overwrite arbitrary files on the affected computer and execute arbitrary commands with the current user permission.
<* Source: Bruce Phillips
Link: http://struts.apache.org/2.x/docs/s2-008.html
Https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt
Http://websec.wordpress.com/2012/01/04/multiple-vulnerabilities-in-apache-struts2-and-property-oriented-programming-with-java/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/