Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.html | mailing list patch |
http://struts.apache.org/release/2.3.x/docs/s2-019.html | patch vendor advisory |
http://www.securityfocus.com/bid/64758 | vdb entry third party advisory |
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html | third party advisory |
http://www.securitytracker.com/id/1029078 | vdb entry third party advisory |