Cross-site request forgery in Apache Struts - CVE-2012-4386

 

Cross-site request forgery in Apache Struts - CVE-2012-4386

Published: May 31, 2024


Vulnerability identifier: #VU90109
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-4386
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to token check mechanism in Apache Struts does not properly validate the token name configuration parameter. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

Apache Struts
IBM Sterling Order Management
Call Center for Commerce

How to mitigate CVE-2012-4386

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

Apache Struts - update to 2.3.5
IBM Sterling Order Management - update to 10.0.0.29
Call Center for Commerce - update to 10.0.12

External References

Related Security Bulletins