Executive Summary

Summary
TitleApache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
Informations
Namecisco-sa-20181107-struts-commons-fileuploadFirst vendor Publication2018-11-07
VendorCiscoLast vendor Modification2018-11-07
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score7.5Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityLow
Cvss Expoit Score10AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031.

The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to an affected system. A successful exploit could allow the attacker to execute arbitrary code or manipulate files on the targeted system.

This advisory will be updated as additional information becomes available.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload"]

BEGIN PGP SIGNATURE

iQJ5BAEBAgBjBQJb5KWYXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczobIQAJJWVSD5Wfx9UAnhLp7ZvWXsPSrv HDVcCE/oq0uyyaNw02IQmnQufaaox0sDmmrDvia+5TePFKclzK6yWF69zs5xY18A mDmNehZHULXHfD6VT2MPJw98sCioudBwGs1OP44BxEs2LOKp4ZnjeKzZeMXD+fpW jdB795tz38uG17bcgx/0OW8uy3JWf80VR5Vrtzj9DZ0htN8p1nmc+oYrzzmmh3du WKrOn3VZt8hN2TvOYj7fEGSXoSQE5HXnNxK4c3d2bx5MojVhlkkI0wTouwHXbsR9 7wSly0cJ7Jlluw4RNMdwXGAeU4X6BLh7/AP+BxryNeHuwfKBO9Ri7tPCV/KpYHnA mBG+lGDdgpqXS8UVoUM4KOeXduQ2r/sWoGafeyunmrWIZD/psu5JQ1qAlqH23N1r IwGzjB8xNF6mg+wrsp153AKcwGySpZlgPsewJrV2Yue51SRT/+VAPYHMvK10nxbm WoRtwpvH8jf5ELvvDMeSExxxiKbdfn2N9p6QTeqI2lxDlznKT4TNvaAndsm7mBZC /1JU9MHMnsPcTFIHk1h4SOY438N6eCZkR6WrK+fsgDC1l/ysaUO1pUyDQWhBw+P0 CZ0A/xcxHlrIuu7iTcTWBWsJsCEnyE8TLJWkJRA5lHUsTKAvI+wmBi8aBUltEKGx eBQz4MP1nkGf0GnW =fewX END PGP SIGNATURE

_______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

%idName
100 %CWE-284Access Control (Authorization) Issues

CPE : Common Platform Enumeration

TypeDescriptionCount
Application10

Snort® IPS/IDS

DateDescription
2017-02-23Apache Commons Library FileUpload unauthorized Java object upload attempt
RuleID : 41390 - Revision : 3 - Type : SERVER-WEBAPP

Nessus® Vulnerability Scanner

DateDescription
2018-11-29Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_d70c9e18f34011e8be460019dbb15b3f.nasl - Type : ACT_GATHER_INFO
2017-08-09Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_c1265e857c9511e793af005056925db4.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2018-11-09 00:18:59
  • First insertion