Path traversal in Apache Struts - CVE-2023-50164

 

Path traversal in Apache Struts - CVE-2023-50164

Published: December 7, 2023 / Updated: March 18, 2025


Vulnerability identifier: #VU83960
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50164
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to input validation error when processing directory traversal sequences in path names. A remote attacker can upload a malicious file to the server and execute it.


Affected software

Apache Struts
IBM Security Guardium
Adobe Experience Manager Forms
IBM Tivoli Application Dependency Discovery Manager
MySQL Enterprise Monitor
Infrastructure Technology
Oracle Communications Policy Management
Aruba Networking ClearPass Policy Manager
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Qradar SIEM

How to mitigate CVE-2023-50164

Install update from vendor's website.

Apache Struts - addressed in versions 2.5.33, 6.3.0.2
Adobe Experience Manager Forms - update to 6.5.19.1
MySQL Enterprise Monitor - update to 8.0.37
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 4.9.1.1, 4.10.0.2
Aruba Networking ClearPass Policy Manager - addressed in versions 6.9.13 Hotfix Patch 7 Q1 2024, 6.10.8 Hotfix Patch 8 Q1 2024, 6.11.7, 6.12.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF04

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins