SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-11776

Apache Struts Remote Code Execution Vulnerability

KEVHIGH 8.1EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.99% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022
Affected
apache/struts · netapp/active iq unified manager · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/snapcenter · oracle/communications policy management · oracle/enterprise manager base platform · oracle/mysql enterprise monitor
Source
security@apache.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-11776

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.