HTTP: Apache Struts 2 Commons FileUpload Insecure Deserialization (1)
This signature detects attempts to exploit a known vulnerability against Apache Struts 2. This vulnerability is due to Apache Struts 2 having a dependency on a vulnerable version of Commons FileUpload. A remote attacker can exploit this vulnerability by sending a specially crafted serialized objects to an application using Apache Struts 2 that also has a suitable attack vector. Successful exploitation can result in arbitrary file upload withing the security context of the target application.
Extended Description
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Affected Products
Apache commons_fileupload
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Apache
7.5