Code Injection in Apache Struts - CVE-2021-31805
Published: April 12, 2022 / Updated: May 9, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation caused by incomplete fix for #VU48815 (CVE-220-17530). Still some of the tag's attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Content Collector for Microsoft SharePoint
Content Collector for File Systems
Content Collector for Email
Content Collector for IBM Connections
IBM Tivoli Netcool/OMNIbus WebGUI
Infrastructure Technology
Netcool Operations Insight
Oracle Hospitality OPERA 5
IBM Tivoli Application Dependency Discovery Manager
MySQL Enterprise Monitor
IBM Security Guardium
Oracle Communications Policy Management
eDiscovery Manager
IBM Sterling Order Management
Avamar Virtual Edition
EMC Avamar
How to mitigate CVE-2021-31805
Netcool Operations Insight - update to 1.6.6
eDiscovery Manager - update to 2.2.2.3.8
IBM Sterling Order Management - update to 10.0.2403.1
Avamar Virtual Edition - update to 19.8
EMC Avamar - update to 19.8
Links to Public Exploits and PoC-codes
- Exploit #9056 - s2-062 (远程代码执行S2-062 CVE-2021-31805验证POC) (May 9, 2023)
- Exploit #8244 - CVE-2021-31805 (S2-061/S2-062 Struts2 远程命令执行漏洞 POC&EXP) (August 13, 2022)
- Exploit #7899 - Struts2_S2-062_CVE-2021-31805 (Apache Struts2 S2-062远程代码执行漏洞(CVE-2021-31805) | 反弹Shell) (May 26, 2022)
- Exploit #7668 - CVE-2021-31805 ( PoC for CVE-2021-31805 (Apache Struts2)) (April 19, 2022)
- Exploit #7651 - CVE-2021-31805 (S2-062 (CVE-2021-31805) / S2-061 / S2-059 RCE) (April 15, 2022)
- Exploit #7648 - s2-062 (远程代码执行S2-062 CVE-2021-31805验证POC) (April 15, 2022)
- Exploit #7646 - S2-062 (Apache Struts2 S2-062远程代码执行漏洞(CVE-2021-31805) 支持批量扫描漏洞及漏洞利用) (April 15, 2022)
External References
Related Security Bulletins
- Remote code execution in Apache Struts
- Code Injection in IBM Content Collector for Email, Content Collector for File Systems, Content Collector for Microsoft SharePoint and Content Collector for IBM Connections
- Multiple vulnerabilities in IBM Security Guardium
- Code Injection in IBM Tivoli Netcool/OMNIbus WebGUI
- Code Injection in Oracle Hospitality OPERA 5
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Infrastructure Technology
- Dell Avamar update for Apache Struts
- Code injection in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in IBM eDiscovery Manager
- Multiple vulnerabilities in IBM Sterling Order Management