First published: Fri May 13 2011(Updated: )
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.struts.xwork:xwork-core | <2.2.2 | 2.2.2 |
Apache Struts 2 | =2.2.1 | |
OpenSymphony XWork | =2.2.1 | |
Webwork | ||
OpenSymphony XWork |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2088 is classified as a medium severity vulnerability affecting Apache Struts 2.2.1 and OpenSymphony XWork 2.2.1.
To fix CVE-2011-2088, upgrade to Apache Struts version 2.2.2 or higher.
CVE-2011-2088 affects Apache Struts 2.2.1 and OpenSymphony XWork version 2.2.1.
CVE-2011-2088 allows remote attackers to potentially obtain sensitive information about internal Java class paths.
No, CVE-2011-2088 is a different vulnerability than CVE-2011-1772.