Lucene search

K
redhatRedHatRHSA-2014:0500
HistoryMay 14, 2014 - 12:00 a.m.

(RHSA-2014:0500) Important: struts security update

2014-05-1400:00:00
access.redhat.com
34

0.973 High

EPSS

Percentile

99.9%

Red Hat Satellite is a systems management tool for Linux-based
infrastructures. It allows for provisioning, monitoring, and remote
management of multiple Linux deployments with a single, centralized tool.

Apache Struts is a framework for building web applications with Java.

It was found that the Struts 1 ActionForm object allowed access to the
‘class’ parameter, which is directly mapped to the getClass() method. A
remote attacker could use this flaw to manipulate the ClassLoader used by
an application server running Struts 1. This could lead to remote code
execution under certain conditions. (CVE-2014-0114)

All Satellite users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For this update to take
effect, the tomcat6 service must be restarted (“service tomcat6 restart”).