Improper input validation in Apache Struts - CVE-2018-11776
Published: August 22, 2018 / Updated: February 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient input validation in cases where namespace value isn't set for a result defined in underlying xml configurations and in same time, its upper action(s) configurations have no or wildcard namespace, or when using url tag which doesn’t have value and action set and in same time, its upper action(s) configurations have no or wildcard namespace.
A remote unauthenticated attacker can compromise the affected system.
Affected software
FlashSystem 840 9840-AE1 & 9843-AE1
Oracle Communications Policy Management
Enterprise Manager Base Platform
FlashSystem 900 9840-AE3 and 9843-AE3
FlashSystem 900 9840-AE2 and 9843-AE2
SAN Volume Controller and Storwize Family
How to mitigate CVE-2018-11776
FlashSystem 900 9840-AE3 and 9843-AE3 - addressed in versions 1.4.8.1, 1.5.2.1
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.4.8.1, 1.5.2.1
SAN Volume Controller and Storwize Family - addressed in versions 7.5.0.13, 7.8.1.8, 8.1.3.3, 8.2.0.2, 8.2.1.0
Links to Public Exploits and PoC-codes
- Exploit #6290 - Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit) (June 17, 2021)
- Exploit #6292 - Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1) (June 17, 2021)
- Exploit #2309 - exphub (Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340) (April 7, 2020)
- Exploit #2207 - cve5scan (5 CVE scan and exploit) (March 18, 2020)
- Exploit #2062 - Apache-Struts-0Day-Exploit (Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts.) (March 18, 2020)
- Exploit #2148 - Apache-Struts-Shodan-Exploit (This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.) (March 18, 2020)
- Exploit #205 - CVE-2018-11776 (CVE-2018-11776(S2-057) EXPLOIT CODE) (March 18, 2020)
- Exploit #206 - CVE-2018-11776-Python-PoC (Working Python test and PoC for CVE-2018-11776, includes Docker lab) (March 18, 2020)
- Exploit #207 - struts-pwn_CVE-2018-11776 ( An exploit for Apache Struts CVE-2018-11776) (March 18, 2020)
- Exploit #208 - S2-057-CVE-2018-11776 (A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)) (March 18, 2020)
- Exploit #1757 - Apache Struts 2 Namespace Redirect OGNL Injection (March 18, 2020)
External References
Related Security Bulletins
- Remote code execution in Apache Struts
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Improper input validation in IBM FlashSystem 840 and 900
- Improper input validation in IBM SAN Volume Controller and Storwize Family
- Improper input validation in Oracle Communications Policy Management