Path traversal in Apache Struts - CVE-2023-50164
Published: December 7, 2023 / Updated: March 18, 2025
Vulnerability identifier: #VU83960
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50164
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences in path names. A remote attacker can upload a malicious file to the server and execute it.
Affected software
Apache Struts
IBM Security Guardium
Adobe Experience Manager Forms
IBM Tivoli Application Dependency Discovery Manager
MySQL Enterprise Monitor
Infrastructure Technology
Oracle Communications Policy Management
Aruba Networking ClearPass Policy Manager
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Qradar SIEM
IBM Security Guardium
Adobe Experience Manager Forms
IBM Tivoli Application Dependency Discovery Manager
MySQL Enterprise Monitor
Infrastructure Technology
Oracle Communications Policy Management
Aruba Networking ClearPass Policy Manager
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Qradar SIEM
How to mitigate CVE-2023-50164
Install update from vendor's website.
Apache Struts - addressed in versions 2.5.33, 6.3.0.2
Adobe Experience Manager Forms - update to 6.5.19.1
MySQL Enterprise Monitor - update to 8.0.37
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 4.9.1.1, 4.10.0.2
Aruba Networking ClearPass Policy Manager - addressed in versions 6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF04
Adobe Experience Manager Forms - update to 6.5.19.1
MySQL Enterprise Monitor - update to 8.0.37
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 4.9.1.1, 4.10.0.2
Aruba Networking ClearPass Policy Manager - addressed in versions 6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF04
Links to Public Exploits and PoC-codes
- Exploit #11217 - CVE-2023-50164-ApacheStruts2-Docker (Vulnerable docker container for Apache Struts 2 RCE CVE-2023-50164) (March 18, 2025)
- Exploit #11209 - cve-2023-50164-poc (Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")) (March 14, 2025)
- Exploit #10587 - CVE-2023-50164-PoC (CVE-2023-50164 PoC Application & Exploit script) (October 11, 2024)
- Exploit #9980 - cve-2023-50164-poc (Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")) (June 14, 2024)
- Exploit #9931 - CVE-2023-50164-Apache-Struts-RCE (A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload parameters that can potentially lead to unauthorized path traversal and r (June 7, 2024)
- Exploit #9499 - Trackplus Allegra Service Desk Module UploadHelper upload Directory Traversal Remote Code Execution Vulnerability (January 15, 2024)
- Exploit #9426 - Apache Struts2 文件上传漏洞分析(CVE-2023-50164) (December 15, 2023)
External References
Related Security Bulletins
- Remote code execution via file upload in Apache Struts
- Adobe Experience Manager (AEM) Forms on JEE update for Apache Struts
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Infrastructure Technology
- Dell Storage Monitoring and Reporting update for Apache Struts
- Multiple vulnerabilities in HPE Aruba Networking ClearPass Policy Manager