An Apache Struts vulnerability was addressed by IBM Social Media Analytics 1.3.0 IF18.
CVEID: CVE-2016-0785
DESCRIPTION: Apache Struts could allow a remote attacker to execute arbitrary code on the system, caused by a double OGNL evaluation of attribute values. By sending specially crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111513 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
IBM Social Media Analytics 1.3
The recommended solution is to apply the following interim fix:
IBM Social Media Analytics 1.3.0 IF18
For users of IBM Social Media Analytics 1.2 IBM recommends upgrading to IBM Social Media Analytics 1.3.
IBM recommends that you review your entire environment to identify vulnerable releases of the open-source Apache Struts and take appropriate mitigation and remediation actions.
None known. Apply Social Media Analytics 1.3.0 IF18 interim fix.
CPE | Name | Operator | Version |
---|---|---|---|
social media analytics | eq | 1.3 | |
social media analytics | eq | any |