Permissions, Privileges, and Access Controls in Apache Struts - CVE-2012-4387
Published: April 17, 2024
Vulnerability identifier: #VU88746
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-4387
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to application does not properly impose security restrictions. A remote attacker can cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
Affected software
Apache Struts
Call Center for Commerce
IBM Sterling Order Management
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2012-4387
Install updates from vendor's website.
Apache Struts - update to 2.3.4.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
External References
- http://secunia.com/advisories/50420
- http://struts.apache.org/2.x/docs/s2-011.html
- http://www.openwall.com/lists/oss-security/2012/09/01/4
- http://www.openwall.com/lists/oss-security/2012/09/01/5
- http://www.securityfocus.com/bid/55346
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78183
- https://issues.apache.org/jira/browse/WW-3860