SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0114

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to…

HIGH 7.5EPSS 99.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 99.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
98.95% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
apache/commons beanutils · apache/struts
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.