In Apache Struts 2.0.0 up to and including 2.3.33 and 2.5 up to and including 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apache struts 2.0.3 |
||
apache struts 2.0.5 |
||
apache struts 2.0.11.1 |
||
apache struts 2.0.12 |
||
apache struts 2.1.4 |
||
apache struts 2.1.6 |
||
apache struts 2.2.3 |
||
apache struts 2.3.1 |
||
apache struts 2.3.6 |
||
apache struts 2.3.8 |
||
apache struts 2.3.14.1 |
||
apache struts 2.3.14.3 |
||
apache struts 2.3.16 |
||
apache struts 2.3.16.2 |
||
apache struts 2.3.17 |
||
apache struts 2.3.21 |
||
apache struts 2.0.1 |
||
apache struts 2.0.2 |
||
apache struts 2.0.14 |
||
apache struts 2.1.0 |
||
apache struts 2.1.1 |
||
apache struts 2.1.2 |
||
apache struts 2.3.1.2 |
||
apache struts 2.3.3 |
||
apache struts 2.3.4 |
||
apache struts 2.3.4.1 |
||
apache struts 2.3.5 |
||
apache struts 2.3.15 |
||
apache struts 2.3.15.1 |
||
apache struts 2.3.15.2 |
||
apache struts 2.3.15.3 |
||
apache struts 2.3.24.3 |
||
apache struts 2.3.25 |
||
apache struts 2.3.26 |
||
apache struts 2.3.27 |
||
apache struts 2.5.3 |
||
apache struts 2.5.4 |
||
apache struts 2.5.5 |
||
apache struts 2.5.6 |
||
apache struts 2.0.7 |
||
apache struts 2.0.8 |
||
apache struts 2.0.9 |
||
apache struts 2.0.10 |
||
apache struts 2.0.11 |
||
apache struts 2.1.8 |
||
apache struts 2.1.8.1 |
||
apache struts 2.2.1 |
||
apache struts 2.2.1.1 |
||
apache struts 2.3.10 |
||
apache struts 2.3.11 |
||
apache struts 2.3.12 |
||
apache struts 2.3.13 |
||
apache struts 2.3.19 |
||
apache struts 2.3.20 |
||
apache struts 2.3.20.1 |
||
apache struts 2.3.20.2 |
||
apache struts 2.3.31 |
||
apache struts 2.3.32 |
||
apache struts 2.3.33 |
||
apache struts 2.5 |
||
apache struts 2.3.23 |
||
apache struts 2.3.28.1 |
||
apache struts 2.3.30 |
||
apache struts 2.5.2 |
||
apache struts 2.5.7 |
||
apache struts 2.5.9 |
||
apache struts 2.0.4 |
||
apache struts 2.0.6 |
||
apache struts 2.0.11.2 |
||
apache struts 2.0.13 |
||
apache struts 2.1.3 |
||
apache struts 2.1.5 |
||
apache struts 2.2.3.1 |
||
apache struts 2.3.1.1 |
||
apache struts 2.3.7 |
||
apache struts 2.3.9 |
||
apache struts 2.3.14 |
||
apache struts 2.3.14.2 |
||
apache struts 2.3.16.1 |
||
apache struts 2.3.16.3 |
||
apache struts 2.3.22 |
||
apache struts 2.3.24.2 |
||
apache struts 2.3.28 |
||
apache struts 2.3.29 |
||
apache struts 2.5.1 |
||
apache struts 2.5.8 |
||
apache struts 2.5.10 |
Big Red issues out-of-band patch for Apache and a few other urgent issues
Oracle has stepped outside its usual quarterly security fix cycle to address the latest Apache Struts 2 vulnerability.
Ever since it emerged at the start of September, CVE-2017-9805 has been (in the words of a former Australian prime minister) “a shiver looking for a spine to crawl up”, because so many vendors use Apache to build Web interfaces and bake Struts 2 into their their Web application framework.
Big Red's sprawling product set meant fixes had to be deployed across more ...
Big Red issues out-of-band patch for Apache and a few other urgent issues
Oracle has stepped outside its usual quarterly security fix cycle to address the latest Apache Struts 2 vulnerability.
Ever since it emerged at the start of September, CVE-2017-9805 has been (in the words of a former Australian prime minister) “a shiver looking for a spine to crawl up”, because so many vendors use Apache to build Web interfaces and bake Struts 2 into their their Web application framework.
Big Red's sprawling product set meant fixes had to be deployed across more ...
Oracle released fixes for a handful of recently patched Apache Struts 2 vulnerabilities, including a critical remote code execution vulnerability (CVE-2017-9805) that could let an attacker take control of an affected system, late last week.
The Apache Software Foundation patched the RCE vulnerability, which affects servers running apps built using the Struts framework and its REST communication plugin, earlier this month.
Scores of Oracle products, roughly two dozen in total, are aff...
Cisco has initiated a mass security audit of all its products that incorporate a version of the Apache Struts framework, recently affected by a series of vulnerabilities, one of which is under active exploitation.
Cisco engineers will test all the software products for four Apache Struts security bugs disclosed last week.
The company is keeping a list of To-Be-Tested, Vulnerable, and Confirmed Not Vulnerable products in two security advisories,
and
.
The first Ci...