CVE-2014-0113
29.04.2014, 10:37
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.Enginsight
Vendor | Product | Version |
---|---|---|
apache | struts | 2.0.0 ≤ 𝑥 < 2.3.16.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References