RULE(RULE ID:306500)

Rule General Information
Release Date: 2020-03-10
Rule Name: Apache Struts ParametersInterceptor ClassLoader Security Bypass Vulnerability (CVE-2014-0094)
Severity:
CVE ID:
Rule Protection Details
Description: The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Others
Reference: SecurityFocusBID:65999
http://jvn.jp/en/jp/JVN19294237/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000045
http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.