The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Vulnerability of Apache Struts 2: multiple vulnerabilities

Synthesis of the vulnerability 

An attacker can use several vulnerabilities of Apache Struts 2.
Vulnerable systems: Struts, RSA Authentication Manager, Unix (platform) ~ not comprehensive, vCenter Server, VMware vSphere.
Severity of this threat: 3/4.
Number of vulnerabilities in this bulletin: 4.
Creation date: 26/05/2014.
Références of this weakness: CERTFR-2014-AVI-282, CERTFR-2019-AVI-403, CVE-2014-0094, CVE-2014-0112, CVE-2014-0113, CVE-2014-0116, ESA-2014-080, S2-020, S2-021, S2-022, VIGILANCE-VUL-14798, VMSA-2014-0007, VMSA-2014-0007.1, VMSA-2014-0007.2.

Description of the vulnerability 

Several vulnerabilities were announced in Apache Struts 2.

An attacker can use the "class" parameter (mapped to getClass()), to manipulate the ClassLoader, in order to execute code. [severity:3/4; CVE-2014-0094, S2-020]

An attacker can use the "class" parameter (mapped to getClass()) via ParametersInterceptor, to manipulate the ClassLoader, in order to execute code. [severity:3/4; CVE-2014-0112, S2-021]

An attacker can use the "class" parameter (mapped to getClass()) via CookieInterceptor, to manipulate the ClassLoader, in order to execute code. [severity:3/4; CVE-2014-0113, S2-021]

An attacker can change the state of a session, to use the "class" parameter (mapped to getClass()) via CookieInterceptor, to manipulate the ClassLoader, in order to execute code. [severity:2/4; CVE-2014-0116, S2-022]
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

This computer weakness impacts software or systems such as Struts, RSA Authentication Manager, Unix (platform) ~ not comprehensive, vCenter Server, VMware vSphere.

Our Vigil@nce team determined that the severity of this vulnerability note is important.

The trust level is of type confirmed by the editor, with an origin of internet client.

This bulletin is about 4 vulnerabilities.

An attacker with a expert ability can exploit this cybersecurity threat.

Solutions for this threat 

Apache Struts: version 2.3.20.
The version 2.3.20 is fixed:
  https://struts.apache.org/

Apache Struts 2: workaround.
A workaround is indicated in the information source.

RSA Authentication Manager: solution for Apache Struts.
The solution is indicated on:
  https://knowledge.rsasecurity.com/

VMware vCenter Operations Management Suite: versions 5.8.2 and 5.7.3.
Versions 5.8.2 and 5.7.3 are fixed:
  https://www.vmware.com/go/download-vcops
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

Computer vulnerabilities tracking service 

Vigil@nce provides computers vulnerabilities patches. The Vigil@nce team tracks computer vulnerabilities impacting systems and applications.