Code Injection in Apache Struts - CVE-2021-31805

 

Code Injection in Apache Struts - CVE-2021-31805

Published: April 12, 2022 / Updated: May 9, 2023


Vulnerability identifier: #VU62084
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-31805
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation caused by incomplete fix for #VU48815 (CVE-220-17530). Still some of the tag's attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache Struts
Content Collector for Microsoft SharePoint
Content Collector for File Systems
Content Collector for Email
Content Collector for IBM Connections
IBM Tivoli Netcool/OMNIbus WebGUI
Infrastructure Technology
Netcool Operations Insight
Oracle Hospitality OPERA 5
IBM Tivoli Application Dependency Discovery Manager
MySQL Enterprise Monitor
IBM Security Guardium
Oracle Communications Policy Management
eDiscovery Manager
IBM Sterling Order Management
Avamar Virtual Edition
EMC Avamar

How to mitigate CVE-2021-31805

Install updates from vendor's website.

Apache Struts - update to 2.5.30
Netcool Operations Insight - update to 1.6.6
eDiscovery Manager - update to 2.2.2.3.8
IBM Sterling Order Management - update to 10.0.2403.1
Avamar Virtual Edition - update to 19.8
EMC Avamar - update to 19.8

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins