CyberSec.Space Logo
返回 CVE 浏览器

CVE-2018-11776

Known Exploited (CISA KEV)HIGH
8.1
CVSS Severity Score
EPSS Score76.1450%
EPSS Percentile93.78th
Published2018年8月22日
Last Modified2025年10月27日

Vulnerability Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Affected Platforms (CPE)

📦
Apache

Struts

>= 2.0.4 and < 2.3.35
📦
Apache

Struts

>= 2.5.0 and < 2.5.17
📦
Netapp

Active Iq Unified Manager

>= 7.3
📦
Netapp

Active Iq Unified Manager

>= 9.5
📦
Netapp

Oncommand Insight

All versions
📦
Netapp

Oncommand Workflow Automation

All versions
📦
Netapp

Snapcenter

All versions
📦
Oracle

Communications Policy Management

< 12.5.0
📦
Oracle

Enterprise Manager Base Platform

= 13.3.0.0
📦
Oracle

Enterprise Manager Base Platform

= 13.4.0.0
📦
Oracle

Mysql Enterprise Monitor

<= 3.4.9.4237
📦
Oracle

Mysql Enterprise Monitor

>= 4.0.0 and <= 4.0.6.5281
📦
Oracle

Mysql Enterprise Monitor

>= 8.0.0 and <= 8.0.2.8191

References & Advisories

相关漏洞威胁