Code Injection in Apache Struts - CVE-2012-0392
Published: January 8, 2012 / Updated: December 17, 2020
Vulnerability identifier: #VU49061
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0392
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Apache Struts
Call Center for Commerce
IBM Sterling Order Management
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2012-0392
Install updates from vendor's website.
Apache Struts - update to 2.3.1.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
Links to Public Exploits and PoC-codes
External References
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html
- http://secunia.com/advisories/47393
- http://struts.apache.org/2.x/docs/s2-008.html
- http://struts.apache.org/2.x/docs/version-notes-2311.html
- http://www.exploit-db.com/exploits/18329
- https://lists.immunityinc.com/pipermail/dailydave/2012-January/000011.html
- https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt