Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-5057Apache Struts vulnerability

CWE-2646 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
56.3%
top 1.88%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 8
Latest updateMay 14

Description

Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDapache/struts2.0.02.3.3

🔴Vulnerability Details

2
GHSA
GHSA-x5vg-p6mw-ffv4: Apache Struts 22022-05-14
CVEList
CVE-2011-5057: Apache Struts 22012-01-08

💥Exploits & PoCs

1
Exploit-DB
Apache Struts 2.0.9/2.1.8 - Session Tampering Security Bypass2011-12-07

📋Vendor Advisories

1
Red Hat
struts: improper access restrictions to collections such as session and request2011-12-21

💬Community

1
Bugzilla
CVE-2011-5057 struts: improper access restrictions to collections such as session and request2012-01-11
CVE-2011-5057 — Apache Struts vulnerability | cvebase