RULE(RULE ID:306212)

Rule General Information
Release Date: 2016-12-15
Rule Name: Apache Struts Wildcard Matching OGNL Code Execution Vulnerability -1 (CVE-2013-2134)
Severity:
CVE ID:
Rule Protection Details
Description: Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:60346
SecurityFocusBID:64758
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://struts.apache.org/development/2.x/docs/s2-015.html