Executive Summary
Summary | |
---|---|
Title | Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018 |
Informations | |||
---|---|---|---|
Name | cisco-sa-20181107-struts-commons-fileupload | First vendor Publication | 2018-11-07 |
Vendor | Cisco | Last vendor Modification | 2018-11-07 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to an affected system. A successful exploit could allow the attacker to execute arbitrary code or manipulate files on the targeted system. This advisory will be updated as additional information becomes available. This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload"] BEGIN PGP SIGNATURE iQJ5BAEBAgBjBQJb5KWYXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczobIQAJJWVSD5Wfx9UAnhLp7ZvWXsPSrv HDVcCE/oq0uyyaNw02IQmnQufaaox0sDmmrDvia+5TePFKclzK6yWF69zs5xY18A mDmNehZHULXHfD6VT2MPJw98sCioudBwGs1OP44BxEs2LOKp4ZnjeKzZeMXD+fpW jdB795tz38uG17bcgx/0OW8uy3JWf80VR5Vrtzj9DZ0htN8p1nmc+oYrzzmmh3du WKrOn3VZt8hN2TvOYj7fEGSXoSQE5HXnNxK4c3d2bx5MojVhlkkI0wTouwHXbsR9 7wSly0cJ7Jlluw4RNMdwXGAeU4X6BLh7/AP+BxryNeHuwfKBO9Ri7tPCV/KpYHnA mBG+lGDdgpqXS8UVoUM4KOeXduQ2r/sWoGafeyunmrWIZD/psu5JQ1qAlqH23N1r IwGzjB8xNF6mg+wrsp153AKcwGySpZlgPsewJrV2Yue51SRT/+VAPYHMvK10nxbm WoRtwpvH8jf5ELvvDMeSExxxiKbdfn2N9p6QTeqI2lxDlznKT4TNvaAndsm7mBZC /1JU9MHMnsPcTFIHk1h4SOY438N6eCZkR6WrK+fsgDC1l/ysaUO1pUyDQWhBw+P0 CZ0A/xcxHlrIuu7iTcTWBWsJsCEnyE8TLJWkJRA5lHUsTKAvI+wmBi8aBUltEKGx eBQz4MP1nkGf0GnW =fewX END PGP SIGNATURE _______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com |
Original Source
Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...) |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-284 | Access Control (Authorization) Issues |
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2017-02-23 | Apache Commons Library FileUpload unauthorized Java object upload attempt RuleID : 41390 - Revision : 3 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-11-29 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_d70c9e18f34011e8be460019dbb15b3f.nasl - Type : ACT_GATHER_INFO |
2017-08-09 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_c1265e857c9511e793af005056925db4.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2018-11-09 00:18:59 |
|