9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Affected (21)
Products: Apache: Struts · Ibm: Storwize V3500 Firmware, Storwize V5000 Firmware, Storwize V7000 Firmware · Lenovo: Storage V5030 Firmware · +4 more
Show all products
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.7.1.6 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V3500 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.7.1.6 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V5000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.7.1.6 |
| Running on/with | Platform Versions |
|---|---|
Ibm Storwize V7000 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.7.1.6 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Storage V5030 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.3.6.0.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.6.5 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (67)
Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Press/Media CoverageThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
ExploitPress/Media Coverage
Source: security@apache.org
MitigationVendor Advisory
Source: security@apache.org
MitigationVendor Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Broken Link
Source: security@apache.org
Broken Link
Source: security@apache.org
ExploitIssue Tracking
Source: security@apache.org
Broken Link
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
ExploitThird Party Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB EntryBroken Link
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Broken LinkThird Party Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party AdvisoryUS Government Resource
Source: security@apache.org
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB EntryBroken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.