Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:758
HistoryJun 06, 2014 - 6:13 p.m.

Class Loader Manipulation With CookieInterceptor

2014-06-0618:13:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.971 High

EPSS

Percentile

99.8%

Struts 2 Core is vulnerable to class loader manipulation vulnerability. The vulnerability exists because the getClass method does not properly restrict access to cookies as it accepts all cookie names when “\*” is used to configure cookiesName parameter which allows remote attackers to manipulate the class loader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.