Back to search
CVE-2014-0094
Published: Mar 10, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
59178
third-party-advisory
x_refsource_SECUNIA
http://www.vmware.com/security/advisories/VMSA-2014-0007.html
x_refsource_CONFIRM
http://www.konakart.com/downloads/ver-7-3-0-0-whats-new
x_refsource_CONFIRM
20140306 [ANN] Struts 2.3.16.1 GA release available - security fix
mailing-list
x_refsource_BUGTRAQ
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
x_refsource_CONFIRM
JVN#19294237
third-party-advisory
x_refsource_JVN
http://struts.apache.org/release/2.3.x/docs/s2-020.html
x_refsource_CONFIRM
JVNDB-2014-000045
third-party-advisory
x_refsource_JVNDB
http://www-01.ibm.com/support/docview.wss?uid=swg21676706
x_refsource_CONFIRM
56440
third-party-advisory
x_refsource_SECUNIA
1029876
vdb-entry
x_refsource_SECTRACK
20140625 NEW VMSA-2014-0007 - VMware product updates address security vulnerabilities in Apache Struts library
mailing-list
x_refsource_BUGTRAQ
65999
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now