HTTP: Apache Struts 2 Developer Mode OGNL Execution

This signature detects attempts to exploit a known vulnerability against Apache Strusts 2. A successful attack can lead to arbitrary code execution.

Extended Description

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.

Affected Products

Apache struts

Short Name
HTTP:MISC:APSTRUTS-DEV-EXEC
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
2 Apache CVE-2012-0394 Developer Execution Mode OGNL Struts
Release Date
06/09/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3650
False Positive
Unknown
Vendors

Apache

CVSS Score

6.8

Found a potential security threat?