VDB
BDU%3A2021-01011
BDU%3A2021-01011
PUBLISHED
CVSS 10 CRITICAL
Уязвимость программной платформы Apache Struts, связанная с недостаточным контролем модификации динамически определённых характеристик объекта, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., Apache Software Foundation | Oracle Financial Services Market Risk Measurement and Management, Oracle Financial Services Data Integration Hub, Struts |
Timeline
- Mar 2, 2021 CVE Published
References
- https://cwiki.apache.org/confluence/display/ww/s2-059 url
- http://packetstormsecurity.com/files/160108/Apache-Struts-2.5.20-Double-OGNL-Evaluation.html url
- http://packetstormsecurity.com/files/160721/Apache-Struts-2-Forced-Multi-OGNL-Evaluation.html url
- https://www.oracle.com/security-alerts/cpujan2021.html advisory