Blog | G5 Cyber Security

The Apache Struts 2 Vulnerability and the Value of Patch Management

Apache Struts is a free, open source framework for creating Java web applications. Its widely used to build corporate websites in sectors including education, government, financial services, retail and media. Apache released a patch for the Struts 2 framework in early March 2017, which fixes an easy-to-exploit vulnerability that allows attackers to execute random code by the web server. An attacker can exploit the flaw by sending an invalid value that causes the software to throw an exception. Instead of merely displaying the cause of the exception, the code that was added by the attacker in the request gets executed.”]

Source: https://securityintelligence.com/the-apache-struts-2-vulnerability-and-the-importance-of-patch-management/

Exit mobile version