• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

Attackers take advantage of Apache Struts vulnerabilities

{{postValue.id}}

Last week, a new and critical flaw in the Apache Struts Web application framework was reported by the developers. According to security researchers, the vulnerability affects a disproportionate number of high-impact websites.

An unauthenticated attacker can easily execute a code in the affected system simply by creating a specially crafted content type HTTP header.

Since last thursday, AlienVault has observed high number of attackers who try to exploit the vulnerability.

More than 400 unique sources are feared to have attempted to exploit the Apache Struts vulnerabilities.

In order to contain the situation AlienVault Labs team have created a Pulse in the OTX with the collection of payloads that are being delivered.

Since so many active threats are plaguing and exploiting the struts, AlienVault recommends their users to upgrade their Apache Struts version as soon as possible.

The vulnerable versions of Apache Struts are:

Struts 2.3.5 - Struts 2.3.31

Struts 2.5 - Struts 2.5.10

Upgrading to the following versions resolves the vulnerability:

Struts 2.3.32

Struts 2.5.10.1

Tags:
grayson
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 5 )

Q

What is Apache Struts CVE 2017 5638?

A

Apache Struts is a framework for building Web applications. Apache Struts is prone to a remote code-execution vulnerability. Specifically, this issue affects the Jakarta based file upload Multipart parser. An attacker can exploit this issue through a malicious Content-Type value.

Q

What is Apache Struts framework?

A

Apache Struts. Apache Struts is a free, open-source, MVC framework for creating elegant, modern Java web applications. It favors convention over configuration, is extensible using a plugin architecture, and ships with plugins to support REST, AJAX and JSON.

Q

How do I check struts version?

A

For windows OS
Open file explorer, search for struts*.jar.
Open struts-core.jar with a unzip tool (e.g. IZArc2Go)
Open META-INF folder and open MANIFEST.MF file with a text editor.
There you will find Specification-Version: with the version number.

Q

What is RCE vulnerability?

A

Remote Code Execution (RCE) The best way to protect a computer from a remote code execution vulnerability is to fix holes that allow an attacker to gain access. Microsoft often releases security patches addressing remote code execution vulnerabilities in its monthly Patch Tuesday fixes.

Q

What does Apache Struts do?

A

Apache Struts 2. ... Apache Struts 2 is an open-source web application framework for developing Java EE web applications. It uses and extends the Java Servlet API to encourage developers to adopt a model–view–controller (MVC) architecture.

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help legeek ?
Installation of the call center module

hello

I wish to install a call center in virtual with issabel, I downloaded the latest version of it , but I don' t arrive to install the call center module in issabel. please help me

thanks!

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.