Improper Handling of Parameters in Apache Struts - CVE-2013-1965
Published: April 17, 2024
Vulnerability identifier: #VU88744
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1965
CWE-ID: CWE-233
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of parameters. A remote unauthenticated attacker can trigger vulnerability and execute arbitrary OGNL code via a crafted parameter name.
Affected software
Apache Struts
SAN Volume Controller and Storwize Family
Sterling Web Channel
Call Center for Commerce
IBM Sterling Order Management
SAN Volume Controller and Storwize Family
Sterling Web Channel
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2013-1965
Install updates from vendor's website.
Apache Struts - update to 2.3.14.3
SAN Volume Controller and Storwize Family - addressed in versions 6.4.1.7, 7.1.0.5
Sterling Web Channel - addressed in versions 9.0.0-SFP1, 9.1.0- SFP1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
SAN Volume Controller and Storwize Family - addressed in versions 6.4.1.7, 7.1.0.5
Sterling Web Channel - addressed in versions 9.0.0-SFP1, 9.1.0- SFP1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1