Lucene search

K
f5F5F5:K60499474
HistoryAug 24, 2018 - 12:00 a.m.

K60499474 : Apache Struts vulnerability CVE-2018-11776

2018-08-2400:00:00
my.f5.com
935

8.5 High

AI Score

Confidence

High

0.975 High

EPSS

Percentile

100.0%

Security Advisory Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when using results with no namespace and in same time, its upper action(s) have no or wildcard namespace. Same possibility when using url tag which doesn’t have value and action set and in same time, its upper action(s) have no or wildcard namespace. (CVE-2018-11776)

Impact

There is no impact; F5 products are not affected by this vulnerability.