'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:Apache Struts 2 Session Tamper
Severity:high
CVE ID:
| Descripiton:
|
Apache Struts 2 is an open-source Web application framework for developing Java EE Web applications. It uses and extends the Java Servlet API to encourage developers to adopt a model-view-controller (MVC) architecture. Apache Struts may allow attackers to bypass certain security restrictions and obtain illegal permission. See more at https://issues.apache.org/jira/browser/WW-2264 and https://issues.apache.org/jira/browser/WW-3631. This rule supports to defend the A6: Vulnerable and Outdated Components, A7: Identification and Authentication Failures and A1: Broken Access Control of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.