Lucene search

K
cveRedhatCVE-2014-0116
HistoryMay 08, 2014 - 10:55 a.m.

CVE-2014-0116

2014-05-0810:55:02
CWE-264
redhat
web.nvd.nist.gov
76
cve-2014-0116
cookieinterceptor
apache struts 2.x
session state manipulation
remote attackers
classloader manipulation
security vulnerability

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.1

Confidence

High

EPSS

0.969

Percentile

99.7%

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to “manipulate” the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.

Affected configurations

Nvd
Node
apachestrutsMatch2.0.0
OR
apachestrutsMatch2.0.1
OR
apachestrutsMatch2.0.2
OR
apachestrutsMatch2.0.3
OR
apachestrutsMatch2.0.4
OR
apachestrutsMatch2.0.5
OR
apachestrutsMatch2.0.6
OR
apachestrutsMatch2.0.7
OR
apachestrutsMatch2.0.8
OR
apachestrutsMatch2.0.9
OR
apachestrutsMatch2.0.10
OR
apachestrutsMatch2.0.11
OR
apachestrutsMatch2.0.11.1
OR
apachestrutsMatch2.0.11.2
OR
apachestrutsMatch2.0.12
OR
apachestrutsMatch2.0.13
OR
apachestrutsMatch2.0.14
OR
apachestrutsMatch2.1.0
OR
apachestrutsMatch2.1.1
OR
apachestrutsMatch2.1.2
OR
apachestrutsMatch2.1.3
OR
apachestrutsMatch2.1.4
OR
apachestrutsMatch2.1.5
OR
apachestrutsMatch2.1.6
OR
apachestrutsMatch2.1.8
OR
apachestrutsMatch2.1.8.1
OR
apachestrutsMatch2.2.1
OR
apachestrutsMatch2.2.1.1
OR
apachestrutsMatch2.2.3
OR
apachestrutsMatch2.2.3.1
OR
apachestrutsMatch2.3.1
OR
apachestrutsMatch2.3.1.1
OR
apachestrutsMatch2.3.1.2
OR
apachestrutsMatch2.3.3
OR
apachestrutsMatch2.3.4
OR
apachestrutsMatch2.3.4.1
OR
apachestrutsMatch2.3.7
OR
apachestrutsMatch2.3.8
OR
apachestrutsMatch2.3.12
OR
apachestrutsMatch2.3.14
OR
apachestrutsMatch2.3.14.1
OR
apachestrutsMatch2.3.14.2
OR
apachestrutsMatch2.3.14.3
OR
apachestrutsMatch2.3.15
OR
apachestrutsMatch2.3.15.1
OR
apachestrutsMatch2.3.15.2
OR
apachestrutsMatch2.3.15.3
OR
apachestrutsMatch2.3.16
OR
apachestrutsMatch2.3.16.1
OR
apachestrutsMatch2.3.16.2
VendorProductVersionCPE
apachestruts2.0.0cpe:2.3:a:apache:struts:2.0.0:*:*:*:*:*:*:*
apachestruts2.0.1cpe:2.3:a:apache:struts:2.0.1:*:*:*:*:*:*:*
apachestruts2.0.2cpe:2.3:a:apache:struts:2.0.2:*:*:*:*:*:*:*
apachestruts2.0.3cpe:2.3:a:apache:struts:2.0.3:*:*:*:*:*:*:*
apachestruts2.0.4cpe:2.3:a:apache:struts:2.0.4:*:*:*:*:*:*:*
apachestruts2.0.5cpe:2.3:a:apache:struts:2.0.5:*:*:*:*:*:*:*
apachestruts2.0.6cpe:2.3:a:apache:struts:2.0.6:*:*:*:*:*:*:*
apachestruts2.0.7cpe:2.3:a:apache:struts:2.0.7:*:*:*:*:*:*:*
apachestruts2.0.8cpe:2.3:a:apache:struts:2.0.8:*:*:*:*:*:*:*
apachestruts2.0.9cpe:2.3:a:apache:struts:2.0.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 501

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.1

Confidence

High

EPSS

0.969

Percentile

99.7%