Code Injection in Apache Struts - CVE-2020-17530
Published: December 8, 2020 / Updated: April 3, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when processing certain tag's attributes. The application performs double evaluation of the code if a developer applied forced OGNL evaluation by using the %{...} syntax. A remote attacker can send a specially crafted request to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Oracle Hospitality OPERA 5
MySQL Enterprise Monitor
Oracle Communications Diameter Intelligence Hub
Netcool Operations Insight
BIG-IP AAM
Oracle Communications Pricing Design Center
Oracle Business Intelligence Enterprise Edition
eDiscovery Manager
Call Center for Commerce
IBM Sterling Order Management
Avamar Virtual Edition
How to mitigate CVE-2020-17530
Netcool Operations Insight - update to 1.6.6
eDiscovery Manager - update to 2.2.2.3.8
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
Avamar Virtual Edition - update to 19.7
Links to Public Exploits and PoC-codes
- Exploit #8955 - CVE-2020-17530 (Struts2 S2-061 远程命令执行漏洞(CVE-2020-17530)) (April 3, 2023)
- Exploit #5070 - CVE-2020-17530-s2-061 () (January 24, 2021)
- Exploit #5009 - CVE-2020-17530 () (January 11, 2021)
- Exploit #4986 - CVE-2020-17530 () (January 3, 2021)
- Exploit #4960 - Apache Struts 2 Forced Multi OGNL Evaluation (December 23, 2020)
- Exploit #4954 - freemarker_RCE_struts2_s2-061 ((cve-2020-17530) struts2_s2-061 freemarker_RCE testscript) (December 23, 2020)
- Exploit #4940 - CVE-2020-17530-strust2-061 (CVE-2020-17530-strust2-061) (December 16, 2020)
- Exploit #4938 - CVE-2020-17530 (S2-061 CVE-2020-17530) (December 16, 2020)
- Exploit #4923 - CVE-2020-17530 (S2-061 的payload,以及对应简单的PoC/Exp) (December 11, 2020)
- Exploit #4920 - CVE-2020-17531 (Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风险极大。提醒我校Apache Struts用户尽快采取安全措施阻止漏洞攻击。) (December 11, 2020)
- Exploit #4919 - CVE-2020-17530 (Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风险极大。提醒我校Apache Struts用户尽快采取安全措施阻止漏洞攻击。) (December 11, 2020)
- Exploit #4918 - CVE-2020-17530 () (December 11, 2020)
- Exploit #4917 - CVE-2020-17530 () (December 11, 2020)
- Exploit #4916 - CVE-2020-17530 (hack,poc) (December 11, 2020)
External References
Related Security Bulletins
- Remote code execution in Apache Struts
- Code injection in BIG-IP AAM Apache Struts component
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle Hospitality OPERA 5
- Multiple vulnerabilities in Oracle Communications Pricing Design Center
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Oracle Communications Diameter Intelligence Hub
- Remote code execution in Dell Avamar Virtual Edition
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM eDiscovery Manager
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM Call Center for Commerce