Permissions, Privileges, and Access Controls in Apache Struts - CVE-2014-0116
Published: May 31, 2024
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to CookieInterceptor in Apache Struts does not properly restrict access to the getClass method, when a wildcard cookiesName value is used. A remote attacker can "manipulate" the ClassLoader and modify the session state via a crafted request.
Affected software
IBM Sterling Order Management
Call Center for Commerce
How to mitigate CVE-2014-0116
IBM Sterling Order Management - update to 10.0.0.29
Call Center for Commerce - update to 10.0.12