iTnews
  • Home
  • News
  • Technology
  • Security

Critical Apache Struts vulnerability menaces enterprises

By Juha Saarinen on Sep 6, 2017 6:40AM
Critical Apache Struts vulnerability menaces enterprises

Users advised to upgrade immediately.

Researchers have discovered a remotely exploitable vulnerability in the Java-based Apache Struts open source web application development framework.

Open source software project analytics firm Lgtm researcher Man Yue Mo said the vulnerability in Struts stems from unsafe deserialisation - or taking data from a certain format and rebuilding it as an object - in the Java programming language.

He was reluctant to provide full details of the flaw due to the seriousness of the vulnerability, but said exploiting it is trivial through the Struts representational state transfer (REST) plug-in. 

"It is incredibly easy to for an attacker to exploit this weakness: all you need is a web browser," Man said.

Struts is a popular framework, with an estimated two-thirds of Fortune 100 companies such as Lockheed Martin, Citigroup, Vodafone, Virgin Atlantic and others using it to develop web applications.

It is used for several airline booking systems as well as in internet banking applications.

The flaw was reported to Apache Struts developers in July, with a patched version of the framework released today.

Users are advised to upgrade to Struts version 2.5.13 immediately. The patched version also addresses two other security issues that can be exploited for denial of service attacks.

In March a vulnerability in the Struts Jakarta multipart parser was found to be under active exploitation by attackers worldwide.

A month later, Australian software vendor Atlassian had to reset all passwords for its Hipchat communications platform after it was hacked via the Struts vulnerability and user data was accessed.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
apacheinfoseclgtmsecuritystruts

Partner Content

Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats
How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Juha Saarinen
Sep 6 2017
6:40AM
0 Comments

Related Articles

  • IBM sprays Log4j bugs in security products
  • Critical 'Log4Shell' RCE zero-day exploited in large numbers
  • VMware, F5, Log4j added to EnemyBot attack targets
  • Cisco next to turn up Spring4Shell-vulnerable products
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Aussie Broadband nears end of NBN PoI fibre rollout

Aussie Broadband nears end of NBN PoI fibre rollout

Australian court finds insurer not liable for ransomware clean-up costs

Australian court finds insurer not liable for ransomware clean-up costs

Defence, DEWR drop $160m on Microsoft software, Azure

Defence, DEWR drop $160m on Microsoft software, Azure

Digital Nation

COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
Criteo to fork out $94.7m for consent breaches
Criteo to fork out $94.7m for consent breaches
Domino’s invests in observability for zero contact delivery
Domino’s invests in observability for zero contact delivery
Australia will lose 11 percent of jobs to automation by 2040: Forrester
Australia will lose 11 percent of jobs to automation by 2040: Forrester
Megatrends shaping the next 20 years: CSIRO
Megatrends shaping the next 20 years: CSIRO
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.