Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
by CIRT Team
Description: The Struts 1 plugin in Apache Struts 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Impact: Successfully exploiting this issue may allow an attacker to execute arbitrary code in the context of the affected application.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
Reference URL’s:
- http://struts.apache.org/docs/s2-048.html
- http://blog.trendmicro.com/trendlabs-security-intelligence/examining-cve-2017-9791-new-apache-struts-remote-code-execution-vulnerability/
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9791
- http://www.securityfocus.com/bid/99484/info
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts