CVE-2013-2251
CRITICAL
9,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH
9,3
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete
Description
AI Translation Available
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,9433
Percentile
1,0th
Updated
EPSS Score Trend (Last 90 Days)
View on Exploit-DB GHDB
vulnerable servers
Google Query:
https://www.google.com/search?q=inurl%3A%22struts%22+filetype%3Aaction
Author: anonymous
Date: 2013-11-25
74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Access Control
Other
Integrity
Non-Repudiation
Potential Impacts:
Read Application Data
Bypass Protection Mechanism
Alter Execution Logic
Other
Hide Activities
Applicable Platforms
All platforms may be affected
Exploit
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code …
Verified Metasploit Framework (MSF)Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)
View Exploit Code →
Exploit
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters …
VerifiedApache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
View Exploit Code →
Application
Siebel Apps - E-Billing by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gp5000 Firmware by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fujitsu:gp5000_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Interstage Business Process Manager Analytics by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:fujitsu:interstage_business_process_manager_analytics:12.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Archiva by Apache
Version Range Affected
From
1.3
(inclusive)
To
1.3.8
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Siebel Apps - E-Billing by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.1.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gp7000F Firmware by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fujitsu:gp7000f_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Siebel Apps - E-Billing by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Struts by Apache
Version Range Affected
From
2.0.0
(inclusive)
To
2.3.15
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Interstage Business Process Manager Analytics by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:fujitsu:interstage_business_process_manager_analytics:12.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Primergy Firmware by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fujitsu:primergy_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Gp-S Firmware by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fujitsu:gp-s_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Sparc Firmware by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fujitsu:sparc_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Archiva by Apache
CPE Identifier
View Detailed Analysis
cpe:2.3:a:apache:archiva:1.2.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Archiva by Apache
CPE Identifier
View Detailed Analysis
cpe:2.3:a:apache:archiva:1.2:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Primepower Firmware by Fujitsu
CPE Identifier
View Detailed Analysis
cpe:2.3:o:fujitsu:primepower_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013…
http://archiva.apache.org/security.html
http://cxsecurity.com/issue/WLB-2014010087
http://osvdb.org/98445
http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Executi…
http://seclists.org/fulldisclosure/2013/Oct/96
http://seclists.org/oss-sec/2014/q1/89
https://exchange.xforce.ibmcloud.com/vulnerabilities/90392
http://struts.apache.org/release/2.3.x/docs/s2-016.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2…
http://www.fujitsu.com/global/support/software/security/products-f/interstage-b…
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.securityfocus.com/bid/61189
http://www.securityfocus.com/bid/64758
http://www.securitytracker.com/id/1029184
http://www.securitytracker.com/id/1032916
http://archiva.apache.org/security.html
http://cxsecurity.com/issue/WLB-2014010087
http://osvdb.org/98445
http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Executi…
http://seclists.org/fulldisclosure/2013/Oct/96
http://seclists.org/oss-sec/2014/q1/89
https://exchange.xforce.ibmcloud.com/vulnerabilities/90392
http://struts.apache.org/release/2.3.x/docs/s2-016.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2…
http://www.fujitsu.com/global/support/software/security/products-f/interstage-b…
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.securityfocus.com/bid/61189
http://www.securityfocus.com/bid/64758
http://www.securitytracker.com/id/1029184
http://www.securitytracker.com/id/1032916