V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
BDU:2022-05999
BDU
CriticalConfirmedExploit available

Уязвимость реализации механизма сопоставления действий DefaultActionMapper программной платформы Apache Struts связана с недостаточной очис…

CVSS
10.0
Critical
EPSS
0.00
p0
Published
2022-01-01
Updated
2022-01-01
Description

Уязвимость реализации механизма сопоставления действий DefaultActionMapper программной платформы Apache Struts связана с недостаточной очисткой входных данных при обработке параметров action:, redirect: и redirectAction: prefix. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код

Tags · CWE
Pre-auth
Affected products
Apache software foundation StrutsCisco systems inc. Cisco identity services engineCisco systems inc. Cisco identity services engineCisco systems inc. Cisco identity services engineCisco systems inc. Cisco identity services engineCisco systems inc. Cisco identity services engineCisco systems inc. Cisco identity services engineCisco systems inc. Cisco identity services engineCisco systems inc. Cisco media experience engine (mxe) 3500 seriesCisco systems inc. Cisco packaged contact center enterpriseCisco systems inc. Cisco packaged contact center enterpriseCisco systems inc. Cisco packaged contact center enterpriseCisco systems inc. Cisco packaged contact center enterpriseCisco systems inc. Cisco packaged contact center enterpriseCisco systems inc. Cisco unified contact center enterpriseCisco systems inc. Cisco unified contact center enterpriseCisco systems inc. Cisco unified contact center enterpriseCisco systems inc. Cisco unified contact center enterpriseCisco systems inc. Cisco unified contact center enterpriseCisco systems inc. Cisco unified sip proxy software
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
27135
exploitdb · https://www.exploit-db.com/exploits/27135
Enterprise
44583
exploitdb · https://www.exploit-db.com/exploits/44583
Enterprise
CVE-2013-2251
github-poc · https://github.com/nth347/CVE-2013-2251
Enterprise
Affected software
ProductVendorStatus
strutsapache software foundationTracked
cisco identity services enginecisco systems inc.Tracked
cisco identity services enginecisco systems inc.Tracked
cisco identity services enginecisco systems inc.Tracked
cisco identity services enginecisco systems inc.Tracked
cisco identity services enginecisco systems inc.Tracked
cisco identity services enginecisco systems inc.Tracked
cisco identity services enginecisco systems inc.Tracked
cisco media experience engine (mxe) 3500 seriescisco systems inc.Tracked
cisco packaged contact center enterprisecisco systems inc.Tracked
cisco packaged contact center enterprisecisco systems inc.Tracked
cisco packaged contact center enterprisecisco systems inc.Tracked
cisco packaged contact center enterprisecisco systems inc.Tracked
cisco packaged contact center enterprisecisco systems inc.Tracked
cisco unified contact center enterprisecisco systems inc.Tracked
cisco unified contact center enterprisecisco systems inc.Tracked
cisco unified contact center enterprisecisco systems inc.Tracked
cisco unified contact center enterprisecisco systems inc.Tracked
cisco unified contact center enterprisecisco systems inc.Tracked
cisco unified sip proxy softwarecisco systems inc.Tracked