VDB
BDU%3A2022-06344
BDU%3A2022-06344
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Уязвимость приложения Apache Struts Showcase программной платформы Apache Struts, позволяющая нарушителю выполнить произвольный код OGNL
Risk Scores
CVSS 2.0
9.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM Corp., Apache Software Foundation | IBM Call Center for Commerce, IBM Platform Symphony, Struts |
Timeline
- Oct 20, 2022 CVE Published
References
- https://cwiki.apache.org/confluence/display/WW/S2-012 url
- https://bugtraq.securityfocus.com/archive url
- https://bugzilla.redhat.com/show_bug.cgi?id=967655 url
- https://access.redhat.com/security/cve/cve-2013-1965 url
- https://github.com/cinno/CVE-2013-1965 url
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-call-center-and-apache-struts-struts-upgrade-strategy-various-cves-see-below/ advisory
- https://www.ibm.com/support/pages/security-bulletin-ibm-platform-symphony-cve-2013-2251-cve-2013-2248-cve-2013-2135-cve-2013-2134-cve-2013-2115-cve-2013-1966-cve-2013-1965-cve-2013-4310 advisory