Remote code execution in Apache Struts - CVE-2017-12611
Published: September 11, 2017 / Updated: April 7, 2020
Vulnerability identifier: #VU8213
CSH Severity: Medium
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12611
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The weakness exists due to the unsafe use of writable expression values in Freemarker content. A remote attacker can add malicious values to writable expressions that the attacker submits to the affected application for processing and execute arbitrary code in the security context of the affected application.
The weakness exists due to the unsafe use of writable expression values in Freemarker content. A remote attacker can add malicious values to writable expressions that the attacker submits to the affected application for processing and execute arbitrary code in the security context of the affected application.
Affected software
Apache Struts
Call Center for Commerce
IBM Sterling Order Management
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2017-12611
Update to version 2.5.12 or 2.3.34.
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
IBM Sterling Order Management - update to 10.0.2403.1
Links to Public Exploits and PoC-codes
- Exploit #2310 - exphub (Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340) (April 7, 2020)
- Exploit #152 - S2-053-CVE-2017-12611 (A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)) (March 18, 2020)