Skip to main content

Apache Struts2 Remote Code Execution Vulnerability

Last Update Date: 8 Mar 2017 11:53 Release Date: 8 Mar 2017 4072 Views

RISK: Extremely High Risk

TYPE: Web services - Web Servers

TYPE: Web Servers

 A vulnerability has been identified in Apache Struts2, which can be exploited by remote attacker to take control of an affected system.

 

NOTE: This vulnerability is being actively exploited in the wild.


Impact

  • Remote Code Execution

System / Technologies affected

  • Version 2.3.5 to 2.3.31
  • Version 2.5 to 2.5.10

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 2.3.32
  • Update to version 2.5.10.1

Vulnerability Identifier


Source


Related Link