First published: Wed May 14 2014(Updated: )
Red Hat Satellite is a systems management tool for Linux-based<br>infrastructures. It allows for provisioning, monitoring, and remote<br>management of multiple Linux deployments with a single, centralized tool.<br>Apache Struts is a framework for building web applications with Java.<br>It was found that the Struts 1 ActionForm object allowed access to the<br>'class' parameter, which is directly mapped to the getClass() method. A<br>remote attacker could use this flaw to manipulate the ClassLoader used by<br>an application server running Struts 1. This could lead to remote code<br>execution under certain conditions. (CVE-2014-0114)<br>All Satellite users are advised to upgrade to these updated packages, which<br>contain a backported patch to correct this issue. For this update to take<br>effect, the tomcat6 service must be restarted ("service tomcat6 restart").<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/struts | <1.3.10-6.ep5.el6 | 1.3.10-6.ep5.el6 |
redhat/struts | <1.3.10-6.ep5.el6 | 1.3.10-6.ep5.el6 |
redhat/struts-core | <1.3.10-6.ep5.el6 | 1.3.10-6.ep5.el6 |
redhat/struts-extras | <1.3.10-6.ep5.el6 | 1.3.10-6.ep5.el6 |
redhat/struts-taglib | <1.3.10-6.ep5.el6 | 1.3.10-6.ep5.el6 |
redhat/struts-tiles | <1.3.10-6.ep5.el6 | 1.3.10-6.ep5.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.