Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20200902-01-STRUTS2
HistorySep 02, 2020 - 12:00 a.m.

Security Advisory - Remote Code Execution vulnerability in Apache Struts2

2020-09-0200:00:00
Huawei Technologies
www.huawei.com
55

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.953 High

EPSS

Percentile

99.4%

The Apache Struts frameworks, when forced, performs double evaluation of attributes’ values assigned to certain tags attributes such as id so it is possible to pass in a value that will be evaluated again when a tag’s attributes will be rendered. With a carefully crafted request, this can lead to Remote Code Execution. The problem only applies when forcing OGNL evaluation inside a Struts tag attribute, when the expression to evaluate references raw, unvalidated input that an attacker is able to directly modify by crafting a corresponding request. (Vulnerability ID: HWPSIRT-2020-49789)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2019-0230.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200902-01-struts2-en

Affected configurations

Vulners
Node
huaweiagile_controller-campusMatchv100r002c00
OR
huaweiagile_controller-campusMatchv100r002c10
OR
huaweiagile_controller-campusMatchv100r002c10spc400
OR
huaweiagile_controller-campusMatchv100r002c10spc403
OR
huaweiagile_controller-campusMatchv100r002c10spc405
OR
huaweiagile_controller-campusMatchv100r002c10spc408
OR
huaweiagile_controller-campusMatchv100r002c10spc409
OR
huaweiagile_controller-campusMatchv100r003c30
OR
huaweiagile_controller-campusMatchv100r003c50
OR
huaweiagile_controller-campusMatchv100r003c60
OR
huaweismsgwMatchv100r001c01lg0701
OR
huaweismsgwMatchv100r001c01lg0801
OR
huaweismsgwMatchv100r001c01lg0801spc001
OR
huaweismsgwMatchv100r001c01lg0901
OR
huaweismsgwMatchv100r001c01lg0901spc001
OR
huaweismsgwMatchv100r002c11lg1901
OR
huaweismsgwMatchv100r002c11lg2501
OR
huaweismsgwMatchv100r002c11lg2601
OR
huaweismsgwMatchv100r002c11lg3001
OR
huaweismsgwMatchv100r002c11lg3201
OR
huaweismsgwMatchv100r002c11lg3501
OR
huaweismsgwMatchv100r002c11lg3701
OR
huaweismsgwMatchv100r002c11lg3801
OR
huaweismsgwMatchv100r003c01lg2401
OR
huaweismsgwMatchv100r003c01lg3501
OR
huaweismsgwMatchv100r003c01lg3601
OR
huaweismsgwMatchv100r003c01lg3601spc001
OR
huaweismsgwMatchv100r003c01lg3701
OR
huaweismsgwMatchv100r003c01lg3801
OR
huaweismsgwMatchv100r003c01lg3901
OR
huaweismsgwMatchv100r003c01lg4001
OR
huaweismsgwMatchv100r003c01lg4101
OR
huaweismsgwMatchv100r003c01lg4101spc001
OR
huaweismsgwMatchv100r003c01lg4201
OR
huaweismsgwMatchv100r003c01lg4301
OR
huaweismsgwMatchv100r003c01lg5101
OR
huaweismsgwMatchv100r003c01lg5201
OR
huaweismsgwMatchv100r003c01lg5401
OR
huaweismsgwMatchv100r003c01lg5501
OR
huaweismsgwMatchv100r003c01lg6001
OR
huaweismsgwMatchv100r003c01lg6101
OR
huaweismsgwMatchv100r003c01lg6201
OR
huaweismsgwMatchv100r003c01lg6301
OR
huaweismsgwMatchv100r003c01lg6701
OR
huaweismsgwMatchv100r003c01lg6801
OR
huaweismsgwMatchv100r003c01lg6901
OR
huaweismsgwMatchv100r003c01lg7001
OR
huaweismsgwMatchv100r003c01lg7101
OR
huaweismsgwMatchv100r003c01lg7201
OR
huaweismsgwMatchv100r003c01lg7301
OR
huaweismsgwMatchv100r003c01lg7401
OR
huaweismsgwMatchv100r003c01lg7701
OR
huaweismsgwMatchv100r003c01lrc001
OR
huaweismsgwMatchv100r003c01lrc003
OR
huaweismsgwMatchv100r003c01lrc008
OR
huaweismsgwMatchv100r003c01lrc009
OR
huaweismsgwMatchv100r003c01lrc010spc001
OR
huaweismsgwMatchv100r003c01lrg001
OR
huaweismsgwMatchv100r003c01lrg002
OR
huaweismsgwMatchv100r003c01lrg003
OR
huaweismsgwMatchv100r003c01lrg009
OR
huaweismsgwMatchv100r003c01lrg020
OR
huaweismsgwMatchv100r003c01lrg021
OR
huaweismsgwMatchv100r003c01lrg022
OR
huaweismsgwMatchv100r003c01lrg024
OR
huaweismsgwMatchv100r003c01lrg025
OR
huaweismsgwMatchv100r003c01lrg029
OR
huaweismsgwMatchv100r003c01lrg030
OR
huaweismsgwMatchv100r003c01lrg032
OR
huaweismsgwMatchv100r003c01lrg033
OR
huaweismsgwMatchv100r003c01lrg034
OR
huaweismsgwMatchv100r003c01lrg037
OR
huaweismsgwMatchv100r003c01lri001
OR
huaweismsgwMatchv100r003c01lri002
OR
huaweismsgwMatchv100r003c01lrm001
OR
huaweismsgwMatchv100r003c01lrs001
OR
huaweismsgwMatchv100r003c01lrw001
OR
huaweismsgwMatchv100r003c01lrw002
OR
huaweismsgwMatchv100r003c01lu0701
OR
huaweismsgwMatchv100r003c01lu0801
OR
huaweismsgwMatchv100r003c01lu0901
OR
huaweismsgwMatchv100r003c01lu1001
OR
huaweismsgwMatchv100r003c01lu1101
OR
huaweismsgwMatchv100r003c01lu1201
OR
huaweismsgwMatchv100r003c01lu1301
OR
huaweismsgwMatchv100r003c01lu1401
OR
huaweismsgwMatchv100r003c01lu1501
OR
huaweismsgwMatchv100r003c01lu1601
OR
huaweismsgwMatchv100r003c01lu1701
OR
huaweismsgwMatchv100r003c01lu2201
OR
huaweismsgwMatchv100r003c01lu2301
OR
huaweismsgwMatchv100r003c01lu2601
OR
huaweismsgwMatchv100r003c01lu2701
OR
huaweiimanager_netecoMatchv600r008c00
OR
huaweiimanager_netecoMatchv600r008c00spc100
OR
huaweiimanager_netecoMatchv600r008c10
OR
huaweiimanager_netecoMatchv600r008c10spc100
OR
huaweiimanager_netecoMatchv600r008c20
OR
huaweiimanager_netecoMatchv600r008c20spc100
OR
huaweiimanager_netecoMatchv600r008c30
OR
huaweiimanager_netecoMatchv600r009c00
OR
huaweiimanager_netecoMatchv600r009c10spc200
OR
huaweiimanager_neteco_6000Matchv600r007c80
OR
huaweiimanager_neteco_6000Matchv600r007c80spc100
OR
huaweiimanager_neteco_6000Matchv600r007c80spc200
OR
huaweiimanager_neteco_6000Matchv600r007c90
OR
huaweiimanager_neteco_6000Matchv600r007c90spc100
OR
huaweiimanager_neteco_6000Matchv600r007c91
OR
huaweiimanager_neteco_6000Matchv600r007c91spc100
OR
huaweiimanager_neteco_6000Matchv600r008c00spc100
OR
huaweiimanager_neteco_6000Matchv600r008c10spc100
OR
huaweiimanager_neteco_6000Matchv600r008c10spc300
OR
huaweiimanager_neteco_6000Matchv600r008c20

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.953 High

EPSS

Percentile

99.4%