Executive Summary

Title Apache Struts Commons FileUpload Library Remote Code Execution Vulnerability Affecting Cisco Products: November 2018
Name cisco-sa-20181107-struts-commons-fileupload First vendor Publication 2018-11-07
Vendor Cisco Last vendor Modification 2018-11-07
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores


On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031.

The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to an affected system. A successful exploit could allow the attacker to execute arbitrary code or manipulate files on the targeted system.

This advisory will be updated as additional information becomes available.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload"]


iQJ5BAEBAgBjBQJb5KWYXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczobIQAJJWVSD5Wfx9UAnhLp7ZvWXsPSrv HDVcCE/oq0uyyaNw02IQmnQufaaox0sDmmrDvia+5TePFKclzK6yWF69zs5xY18A mDmNehZHULXHfD6VT2MPJw98sCioudBwGs1OP44BxEs2LOKp4ZnjeKzZeMXD+fpW jdB795tz38uG17bcgx/0OW8uy3JWf80VR5Vrtzj9DZ0htN8p1nmc+oYrzzmmh3du WKrOn3VZt8hN2TvOYj7fEGSXoSQE5HXnNxK4c3d2bx5MojVhlkkI0wTouwHXbsR9 7wSly0cJ7Jlluw4RNMdwXGAeU4X6BLh7/AP+BxryNeHuwfKBO9Ri7tPCV/KpYHnA mBG+lGDdgpqXS8UVoUM4KOeXduQ2r/sWoGafeyunmrWIZD/psu5JQ1qAlqH23N1r IwGzjB8xNF6mg+wrsp153AKcwGySpZlgPsewJrV2Yue51SRT/+VAPYHMvK10nxbm WoRtwpvH8jf5ELvvDMeSExxxiKbdfn2N9p6QTeqI2lxDlznKT4TNvaAndsm7mBZC /1JU9MHMnsPcTFIHk1h4SOY438N6eCZkR6WrK+fsgDC1l/ysaUO1pUyDQWhBw+P0 CZ0A/xcxHlrIuu7iTcTWBWsJsCEnyE8TLJWkJRA5lHUsTKAvI+wmBi8aBUltEKGx eBQz4MP1nkGf0GnW =fewX END PGP SIGNATURE

_______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-284 Access Control (Authorization) Issues

CPE : Common Platform Enumeration

Application 10

Snort® IPS/IDS

Date Description
2017-02-23 Apache Commons Library FileUpload unauthorized Java object upload attempt
RuleID : 41390 - Revision : 3 - Type : SERVER-WEBAPP

Nessus® Vulnerability Scanner

Date Description
2018-11-29 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_d70c9e18f34011e8be460019dbb15b3f.nasl - Type : ACT_GATHER_INFO
2017-08-09 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_c1265e857c9511e793af005056925db4.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
Date Informations
2018-11-09 00:18:59
  • First insertion