Red Hat Bugzilla – Bug 773167
CVE-2012-0394 struts2: remote execution of arbitrary commands when developer mode is used
Last modified: 2014-09-07 22:18:41 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-0394 to the following vulnerability: Name: CVE-2012-0394 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0394 Assigned: 20120108 Reference: http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html Reference: http://www.exploit-db.com/exploits/18329 Reference: http://struts.apache.org/2.x/docs/s2-008.html Reference: http://struts.apache.org/2.x/docs/version-notes-2311.html Reference: https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
This issue only affects struts 2.
Statement: Not Vulnerable. This issue does not affect the versions of struts as shipped with various Red Hat products.