RULE(RULE ID:306359)

Rule General Information
Release Date: 2015-01-09
Rule Name: Apache Struts DefaultActionMapper Prefixing Parameters Arbitrary Site Redirect Vulnerability -2 (CVE-2013-2248)
Severity:
CVE ID:
Rule Protection Details
Description: Apache Struts contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the 'redirect:' and 'redirectAction:' prefixing parameters upon submission to DefaultActionMapper.
Impact: Remote code execution
Affected OS: Windows
Reference: CVE-2013-2248
Solutions
Update vendor's patch.