Red Hat Bugzilla – Bug 773150
CVE-2011-5057 struts: improper access restrictions to collections such as session and request
Last modified: 2012-01-12 23:10:12 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-5057 to the following vulnerability: Name: CVE-2011-5057 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5057 Assigned: 20120108 Reference: http://codesecure.blogspot.com/2011/12/struts-2-session-tampering-via.html Reference: https://issues.apache.org/jira/browse/WW-2264 Reference: https://issues.apache.org/jira/browse/WW-3631 Reference: http://secunia.com/advisories/47109 Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
This issue only affects struts 2.
Statement: Not Vulnerable. This issue does not affect the versions of struts as shipped with various Red Hat products.