CVE-2011-2088: Infoleak
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2088?
CVE-2011-2088 is classified as a medium severity vulnerability affecting Apache Struts 2.2.1 and OpenSymphony XWork 2.2.1.
How do I fix CVE-2011-2088?
To fix CVE-2011-2088, upgrade to Apache Struts version 2.2.2 or higher.
What applications are affected by CVE-2011-2088?
CVE-2011-2088 affects Apache Struts 2.2.1 and OpenSymphony XWork version 2.2.1.
What type of information can be leaked due to CVE-2011-2088?
CVE-2011-2088 allows remote attackers to potentially obtain sensitive information about internal Java class paths.
Is CVE-2011-2088 the same as CVE-2011-1772?
No, CVE-2011-2088 is a different vulnerability than CVE-2011-1772.