Skip to main content
x

Apache Struts ClassLoader Manipulation တွင် Security Bypass Vulnerability ရှိနေ

Apache Struts ClassLoader Manipulation တွင် Security Bypass Vulnerability ရှိနေကြောင်းကို (၆.၈.၂ဝ၁၄)ရက် နေ့ တွင် SecurityFocus မှ ထုတ်ပြန်အသိပေးခဲ့ပါသည်။ Attacker များသည် ၄င်းအားနည်းချက်ကို အသုံးပြု၍ Security ကန့်သတ်ချက်များကိုကျော်ပြီး Unauthorized Action များကို ပြုလုပ်သွားနိုင်သည့်အပြင် အခြားသော Attack များကိုလည်း ဆက်လက်လုပ်ဆောင်သွားနိုင်မည်ဖြစ်သည်။ Vulnerability ရှိနေသော Apache Struts version များမှာ 1.0.0 မှ 1.3.10 ထိဖြစ်သည်။
အသေးစိတ်ကို အောက်ပါ Link များတွင်ကြည့်ရှုနိုင်ပါသည်။

http://www.securityfocus.com/bid/67121/discuss

http://www.exploit-db.com/exploits/33142/

http://www-01.ibm.com/support/docview.wss?uid=swg21675898

Analysis

An Open Source Apache Struts V1 ClassLoader manipulation vulnerability affects the web application server that is used by the administration console. It does not affect enterprise search applications or the content analytics miner.