CVE-2014-0114
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 99.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 98.95% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/commons beanutils · apache/struts
- Source
- secalert@redhat.com
References
- http://advisories.mageia.org/MGASA-2014-0219.html
- http://apache-ignite-developers.2346864.n4.nabble.com/CVE-2014-0114-Apache-Ignite-is-vulnerable-to-existing-CVE-2014-0114-td31205.html
- http://commons.apache.org/proper/commons-beanutils/javadocs/v1.9.2/RELEASE-NOTES.txt
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136958.html
- http://marc.info/?l=bugtraq&m=140119284401582&w=2
- http://marc.info/?l=bugtraq&m=140801096002766&w=2
- http://marc.info/?l=bugtraq&m=141451023707502&w=2
- http://openwall.com/lists/oss-security/2014/06/15/10
- http://openwall.com/lists/oss-security/2014/07/08/1
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/57477
- http://secunia.com/advisories/58710
- http://secunia.com/advisories/58851
- http://secunia.com/advisories/58947
- http://secunia.com/advisories/59014
- http://secunia.com/advisories/59118
- http://secunia.com/advisories/59228
- http://secunia.com/advisories/59245
- http://secunia.com/advisories/59246
- http://secunia.com/advisories/59430
- http://secunia.com/advisories/59464
- http://secunia.com/advisories/59479
- http://secunia.com/advisories/59480
- http://secunia.com/advisories/59704
- http://secunia.com/advisories/59718
- http://secunia.com/advisories/60177
- http://secunia.com/advisories/60703
- http://www-01.ibm.com/support/docview.wss?uid=swg21674128
- http://www-01.ibm.com/support/docview.wss?uid=swg21674812
- http://www-01.ibm.com/support/docview.wss?uid=swg21675266
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.