|
|||
Rule General Information |
---|
Release Date: | 2017-03-10 | |
Rule Name: | Apache Struts Dynamic Method Invocation Remote Code Execution Vulnerability (CVE-2016-4438) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions. | |
Impact: | An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Mac OS, Other Unix, FreeBSD, Linux | |
Reference: | SecurityFocusBID:87327 SecurityFocusBID:91787 SecurityTrackerID:1035665 ExploitDB:39756 |
|
Solutions |
---|
More advisories have been published on the website, please visit for more suggestions: http://struts.apache.org/docs/s2-032.html |