vendor:
Struts2
by:
Anonymous
N/A
CVSS
N/A
Remote Code Execution
94
CWE
Product Name: Struts2
Affected Version From: Struts 2.3.5 - Struts 2.3.31
Affected Version To: Struts 2.5 - Struts 2.5.10
Patch Exists: YES
Related CWE: CVE-2017-5638
CPE: a:apache:struts:2.3.5
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2017
Apache Struts2 S2-033 Remote Code Execution Vulnerability
Apache Struts2 S2-033 is a remote code execution vulnerability that allows an attacker to execute arbitrary code on the vulnerable server. The vulnerability is caused by the improper handling of the '#_memberAccess' parameter in the Struts2 framework. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious code in the '#_memberAccess' parameter. This will allow the attacker to execute arbitrary code on the vulnerable server.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of Apache Struts2. Additionally, it is recommended to disable the '#_memberAccess' parameter in the Struts2 configuration file.