VDB
JVNDB-2013-003469
JVNDB-2013-003469
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Apache Struts contains a remote command execution vulnerability. Apache Struts provided by the Apache Software Foundation is a software framework for creating Java web applications. Apache Struts contains a remote command execution vulnerability. This issue is the same issue that the developer published as S2-016 on July 16, 2013 Note that attacks leveraging this vulnerability have been confirmed. Takeshi Terada of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Timeline
- Jul 18, 2013 CVE Published
- Jul 27, 2013 PoC Published
- Jan 14, 2014 PoC Published
- Aug 20, 2015 PoC Published
- May 29, 2018 PoC Published
- Oct 15, 2020 PoC Published
- Oct 16, 2020 PoC Published
- Jun 14, 2023 PoC Published
- Dec 24, 2024 PoC Published
- Feb 6, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Feb 23, 2025 PoC Published
References
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html url
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html url
- apache-archiva-ognl-command-exec(90392) vdb
- 20131013 Apache Software Foundation A Subsite Remote command execution mailing-list
- http://cxsecurity.com/issue/WLB-2014010087 url
- 20131023 Apache Struts 2 Command Execution Vulnerability in Multiple Cisco Products vendor-advisory
- http://struts.apache.org/release/2.3.x/docs/s2-016.html url
- http://archiva.apache.org/security.html url
- 98445 vdb
- 1032916 vdb
- 61189 vdb
- 1029184 vdb
- 64758 vdb
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html url
- [oss-security] 20140114 Re: CVE Request: Apache Archiva Remote Command Execution 0day mailing-list
- http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Execution.html url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2251 url