BDU:2015-00402HighConfirmedExploit available
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Share link
Anyone with the link can open this vulnerability.
Уязвимость реализации метода getClass программной платформы Apache Struts связана с недостатками разграничения доступа при использовании кл…
CVSS
7.1
High
EPSS
0.00
p0
Published
2015-01-01
Updated
2015-01-01
Description
Уязвимость реализации метода getClass программной платформы Apache Struts связана с недостатками разграничения доступа при использовании класса ParametersInterceptor с параметром class. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код путем отправки специально созданного запроса
Tags · CWE
Pre-auth
Affected products
Apache software foundation StrutsBroadcom inc. Vmware aria automation orchestratorBroadcom inc. Vmware aria operationsBroadcom inc. Vmware aria operationsIbm corp. Ibm sterling field salesIbm corp. Ibm sterling field salesIbm corp. Ibm sterling field salesIbm corp. Ibm sterling field salesIbm corp. Ibm sterling field salesIbm corp. Ibm sterling order managementIbm corp. Ibm sterling selling and fulfillment foundationIbm corp. Ibm sterling selling and fulfillment foundationIbm corp. Ibm sterling selling and fulfillment foundationIbm corp. Ibm sterling selling and fulfillment foundationIbm corp. Ibm sterling selling and fulfillment foundationIbm corp. Ibm sterling web channelIbm corp. Ibm sterling web channelOracle corp. Mysql enterprise monitorOracle corp. Mysql enterprise monitorOracle corp. Webcenter sites
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
33142
exploitdb · https://www.exploit-db.com/exploits/33142
41690
exploitdb · https://www.exploit-db.com/exploits/41690
Affected products
| Product | Vendor | Status |
|---|---|---|
| struts | apache software foundation | Tracked |
| vmware aria automation orchestrator | broadcom inc. | Tracked |
| vmware aria operations | broadcom inc. | Tracked |
| vmware aria operations | broadcom inc. | Tracked |
| ibm sterling field sales | ibm corp. | Tracked |
| ibm sterling field sales | ibm corp. | Tracked |
| ibm sterling field sales | ibm corp. | Tracked |
| ibm sterling field sales | ibm corp. | Tracked |
| ibm sterling field sales | ibm corp. | Tracked |
| ibm sterling order management | ibm corp. | Tracked |
| ibm sterling selling and fulfillment foundation | ibm corp. | Tracked |
| ibm sterling selling and fulfillment foundation | ibm corp. | Tracked |
| ibm sterling selling and fulfillment foundation | ibm corp. | Tracked |
| ibm sterling selling and fulfillment foundation | ibm corp. | Tracked |
| ibm sterling selling and fulfillment foundation | ibm corp. | Tracked |
| ibm sterling web channel | ibm corp. | Tracked |
| ibm sterling web channel | ibm corp. | Tracked |
| mysql enterprise monitor | oracle corp. | Tracked |
| mysql enterprise monitor | oracle corp. | Tracked |
| webcenter sites | oracle corp. | Tracked |
Showing first 20 of 22
Source databases
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Related vulnerabilities