First published: Fri May 13 2011(Updated: )
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Struts | =2.2.1 | |
OpenSymphony XWork | =2.2.1 | |
OpenSymphony XWork | ||
OpenSymphony WebWork | ||
maven/org.apache.struts.xwork:xwork-core | <2.2.2 | 2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.