Apache Commons Collections Java library insecurely deserializes data
- https://blogs.oracle.com/security/entry/security_alert_cve_2015_4852
Nov 10, 2015 - "This Security Alert addresses security issue CVE-2015-4852, a deserialization vulnerability involving Apache Commons and Oracle WebLogic Server. This is a remote code execution vulnerability and is remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password…"
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4852
>> https://cxf.apache.org/security-advisories.data/CVE-2015-5253.txt.asc
"… Severity: Major
Migration:
CXF 2.7.x users should upgrade to 2.7.18 or later as soon as possible.
CXF 3.0.x users should upgrade to 3.0.7 or later as soon as possible.
CXF 3.1.x users should upgrade to 3.1.3 or later as soon as possible…"
Apache Tomcat - v6.x, 7.x, 8.x, 9.x / updates released
- https://en.wikipedia.org/wiki/Apache_Tomcat
"Apache Tomcat, often referred to as Tomcat, is an open-source web server developed by the Apache Software Foundation (ASF). Tomcat implements several Java EE specifications including Java Servlet, JavaServer Pages (JSP), Java EL, and WebSocket, and provides a "pure Java" HTTP web server environment for Java code to run in. Tomcat is developed and maintained by an open community of developers under the auspices of the Apache Software Foundation… and is open-source software…
> https://en.wikipedia.org/wiki/Apache_Tomcat#High_availability
A high-availability feature has been added to facilitate the scheduling of system upgrades (e.g. new releases, change requests) without affecting the live environment. This is done by dispatching live traffic requests to a temporary server on a different port while the main server is upgraded on the main port. It is very useful in handling user requests on high-traffic web applications…"
- http://www.securitytracker.com/id/1035069
CVE Reference: CVE-2015-5346, CVE-2015-5351, CVE-2016-0706, CVE-2016-0714, CVE-2016-0763
Feb 22 2016
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 6.x, 7.x, 8.x, 9.x
Impact: A remote user can bypass security controls on the target system.
A remote user can obtain potentially sensitive information on the target system.
A remote user can hijack the target user's session.
Solution: The vendor has issued a fix (6.0.45, 7.0.68, 8.0.32, 9.0.0.M3)…
Apache Struts - 2.3.32 / 2.5.10.1 released
- https://isc.sans.edu/diary.html?storyid=22169
2017-03-09 - "On Monday, Apache released a patch for the Struts 2 framework [1]. The patch fixes an easy to exploit vulnerability in the multipart parser that is typically used for file uploads. A Metasploit module was released that same day, and some readers reported seeing exploit attempts in the wild.
You should be running Struts 2.3.32 or 2.5.10.1. All prior versions are vulnerable.
Struts 2 is a Java framework that is commonly used by Java-based web applications. It is also knowns as "Jakarta Struts" and "Apache Struts". The Apache project currently maintains Struts. The vulnerability allows an attacker to include code in the "Content-Type" header of an HTTP request. The code will then be executed by the web server…"
- http://www.securitytracker.com/id/1037973
CVE Reference: CVE-2017-5638
Mar 9 2017
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
Version(s): 2.3.5 - 2.3.31, 2.5 - 2.5.10 …
Impact: A remote user can execute arbitrary operating system commands on the target system.
Solution: The vendor has issued a fix (2.3.32, 2.5.10.1)…
___