Code Injection in Apache Struts - CVE-2012-0392

 

Code Injection in Apache Struts - CVE-2012-0392

Published: January 8, 2012 / Updated: December 17, 2020


Vulnerability identifier: #VU49061
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0392
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper access restrictions within the CookieInterceptor component in Apache Struts. A remote attacker can send a specially crafted HTTP Cookie header that triggers Java code execution through a static method and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache Struts
Call Center for Commerce
IBM Sterling Order Management

How to mitigate CVE-2012-0392

Install updates from vendor's website.

Apache Struts - update to 2.3.1.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins