Input validation error in Apache Struts - CVE-2013-2248
Published: April 17, 2024
Vulnerability identifier: #VU88759
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2248
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform redirect attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
Affected software
Apache Struts
SAN Volume Controller and Storwize Family
Sterling Web Channel
Call Center for Commerce
IBM Sterling Order Management
SAN Volume Controller and Storwize Family
Sterling Web Channel
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2013-2248
Install updates from vendor's website.
Apache Struts - update to 2.3.15.1
SAN Volume Controller and Storwize Family - addressed in versions 6.4.1.7, 7.1.0.5
Sterling Web Channel - addressed in versions 9.0.0-SFP1, 9.1.0- SFP1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
SAN Volume Controller and Storwize Family - addressed in versions 6.4.1.7, 7.1.0.5
Sterling Web Channel - addressed in versions 9.0.0-SFP1, 9.1.0- SFP1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
Links to Public Exploits and PoC-codes
External References
- http://struts.apache.org/release/2.3.x/docs/s2-017.html
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
- http://www.securityfocus.com/bid/61196
- http://www.securityfocus.com/bid/64758