Skip to main content

Apache Struts 2 Remote Code Execution Vulnerability

Last Update Date: 24 Aug 2018 Release Date: 23 Aug 2018 4488 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in Apache Struts 2. A remote attacker can exploit this vulnerability to perform remote code execution on the targeted system.

 

Notes:

  • The exploit code is publicly available.

 


Impact

  • Remote Code Execution

System / Technologies affected

  •  Apache Struts 2 versions 2.3 to 2.3.34, 2.5 to 2.5.16

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to version 2.3.35 or 2.5.17

Vulnerability Identifier


Source


Related Link