V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
BDU:2022-05996
BDU
HighConfirmedExploit available

Уязвимость реализации механизма Dynamic Method Invocation (DMI) программной платформы Apache Struts связана с непринятием мер по очистке вх…

CVSS
8.1
High
EPSS
0.00
p0
Published
2022-01-01
Updated
2022-01-01
Description

Уязвимость реализации механизма Dynamic Method Invocation (DMI) программной платформы Apache Struts связана с непринятием мер по очистке входных данных. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить произвольный код

Tags · CWE
Pre-auth
Affected products
Apache software foundation StrutsApache software foundation StrutsApache software foundation StrutsIbm corp. Ibm call center for commerceIbm corp. Ibm call center for commerceOracle corp. Micros retail xbri loss preventionOracle corp. Micros retail xbri loss preventionOracle corp. Micros retail xbri loss preventionOracle corp. Micros retail xbri loss preventionOracle corp. Micros retail xbri loss preventionOracle corp. Micros retail xbri loss preventionOracle corp. Oracle flexcube private bankingOracle corp. Oracle flexcube private bankingOracle corp. Oracle flexcube private bankingOracle corp. Oracle flexcube private bankingOracle corp. Oracle flexcube private bankingOracle corp. Oracle flexcube private bankingOracle corp. Siebel apps - e-billing
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
39756
exploitdb · https://www.exploit-db.com/exploits/39756
Enterprise
Affected software
ProductVendorStatus
strutsapache software foundationTracked
strutsapache software foundationTracked
strutsapache software foundationTracked
ibm call center for commerceibm corp.Tracked
ibm call center for commerceibm corp.Tracked
micros retail xbri loss preventionoracle corp.Tracked
micros retail xbri loss preventionoracle corp.Tracked
micros retail xbri loss preventionoracle corp.Tracked
micros retail xbri loss preventionoracle corp.Tracked
micros retail xbri loss preventionoracle corp.Tracked
micros retail xbri loss preventionoracle corp.Tracked
oracle flexcube private bankingoracle corp.Tracked
oracle flexcube private bankingoracle corp.Tracked
oracle flexcube private bankingoracle corp.Tracked
oracle flexcube private bankingoracle corp.Tracked
oracle flexcube private bankingoracle corp.Tracked
oracle flexcube private bankingoracle corp.Tracked
siebel apps - e-billingoracle corp.Tracked