漏洞信息详情
Apache Struts 输入验证错误漏洞
- CNNVD编号:CNNVD-201404-581
- 危害等级: 高危
- CVE编号:
CVE-2014-0114
- 漏洞类型:
输入验证错误
- 发布时间:
2014-04-30
- 威胁类型:
远程
- 更新时间:
2021-04-20
- 厂 商:
apache - 漏洞来源:
Rene Gielen -
漏洞简介
Apache Struts是美国阿帕奇(Apache)软件基金会的一个开源项目,是一套用于创建企业级Java Web应用的开源MVC框架,主要提供两个版本框架产品,Struts 1和Struts 2。
Apache Struts 1.x版本至1.3.10版本中的Apache Commons BeanUtils 1.9.2及之前版本中存在输入验证错误漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。
参考网址
来源:MLIST
链接:http://openwall.com/lists/oss-security/2014/06/15/10
来源:MISC
来源:MLIST
来源:MLIST
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2995
来源:CONFIRM
链接:https://issues.apache.org/jira/browse/BEANUTILS-463
来源:SECUNIA
链接:http://secunia.com/advisories/57477
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21675898
来源:MISC
来源:MLIST
链接:http://openwall.com/lists/oss-security/2014/07/08/1
来源:MLIST
来源:MISC
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20140911-0001/
来源:MLIST
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/59430
来源:MLIST
来源:MLIST
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2014/Dec/23
来源:SECUNIA
链接:http://secunia.com/advisories/58851
来源:CONFIRM
链接:http://advisories.mageia.org/MGASA-2014-0219.html
来源:MISC
来源:MLIST
来源:CONFIRM
链接:https://www.vmware.com/security/advisories/VMSA-2014-0012.html
来源:SECUNIA
链接:http://secunia.com/advisories/59704
来源:MLIST
来源:MLIST
来源:MISC
来源:MLIST
来源:MLIST
来源:MISC
来源:SECUNIA
链接:http://secunia.com/advisories/59480
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21676091
来源:MISC
来源:CONFIRM
链接:http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
来源:SECUNIA
链接:http://secunia.com/advisories/59246
来源:SECUNIA
链接:http://secunia.com/advisories/59245
来源:SECUNIA
链接:http://secunia.com/advisories/59479
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/59118
来源:MLIST
来源:MISC
来源:MLIST
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/58947
来源:MLIST
来源:CONFIRM
链接:http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
来源:MLIST
来源:MISC
来源:MLIST
来源:CONFIRM
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1091938
来源:MLIST
来源:FEDORA
链接:http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136958.html
来源:MLIST
来源:GENTOO
链接:https://security.gentoo.org/glsa/201607-09
来源:SECUNIA
链接:http://secunia.com/advisories/59014
来源:CONFIRM
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1116665
来源:SECUNIA
链接:http://secunia.com/advisories/58710
来源:MLIST
来源:MISC
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21675266
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21675387
来源:CONFIRM
链接:http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
来源:CONFIRM
链接:https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21676110
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/534161/100/0/threaded
来源:MLIST
来源:CONFIRM
链接:http://commons.apache.org/proper/commons-beanutils/javadocs/v1.9.2/RELEASE-NOTES.txt
来源:CONFIRM
链接:http://www.vmware.com/security/advisories/VMSA-2014-0008.html
来源:SECUNIA
链接:http://secunia.com/advisories/59464
来源:BID
链接:https://www.securityfocus.com/bid/67121
来源:MLIST
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2669
来源:MISC
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21675972
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21676303
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674128
来源:CONFIRM
链接:http://www.vmware.com/security/advisories/VMSA-2014-0012.html
来源:MLIST
来源:DEBIAN
链接:http://www.debian.org/security/2014/dsa-2940
来源:MLIST
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21677110
来源:BID
链接:http://www.securityfocus.com/bid/67121
来源:CONFIRM
链接:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755
来源:HP
链接:http://marc.info/?l=bugtraq&m=140119284401582&w=2
来源:MLIST
来源:HP
链接:http://marc.info/?l=bugtraq&m=141451023707502&w=2
来源:SECUNIA
链接:http://secunia.com/advisories/59228
来源:CONFIRM
链接:http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
来源:MLIST
来源:MLIST
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21676931
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21675689
来源:CONFIRM
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21676375
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/60177
来源:MLIST
来源:MANDRIVA
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2014:095
来源:MLIST
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
来源:CONFIRM
链接:http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/60703
来源:SECUNIA
链接:http://secunia.com/advisories/59718
来源:CONFIRM
链接:https://www.ibm.com/support/docview.wss?uid=swg21675496
来源:CONFIRM
链接:http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg24037622
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21677352
来源:jvn.jp
链接:http://jvn.jp/en/jp/JVN30962312/index.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21680194
来源:support.f5.com
链接:http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15282.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg24037424
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21680698
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21679331
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674905
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21674113
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21673877
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21673878
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21676091
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21674613
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21677298
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674812
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21676485
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21675496
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21677449
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674339
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674016
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674017
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21674191
来源:www-304.ibm.com
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674310
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21677802
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21675387
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21680716
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21678359
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673422
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673982
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674110
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673992
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674104
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21674099
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673695
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21673508
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21673757
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004807
来源:rhn.redhat.com
链接:https://rhn.redhat.com/errata/RHSA-2014-0500.html
来源:rhn.redhat.com
链接:https://rhn.redhat.com/errata/RHSA-2014-0497.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg24037506
来源:www.oracle.com
链接:https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
来源:www.oracle.com
链接:http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg24037409
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg24037825
来源:www.hitachi.co.jp
链接:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-020/index.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21678830
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg24037507
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg1IV61058
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg1IV61039
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg27042184
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg27042185
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg27042186
来源:struts.apache.org
链接:http://struts.apache.org/release/2.3.x/docs/s2-021.html
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21676646
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21680848
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg1IV61061
来源:h20564.www2.hpe.com
链接:https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05324755
来源:h20564.www2.hp.com
链接:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04473828
来源:h20564.www2.hp.com
链接:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04399728
来源:rhn.redhat.com
链接:https://rhn.redhat.com/errata/RHSA-2014-0498.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673101
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673944
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673098
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21676375
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21672316
来源:www.hitachi.co.jp
链接:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-018/index.html
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21673663
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg21675822
来源:www-01.ibm.com
链接:http://www-01.ibm.com/support/docview.wss?uid=swg27042296
来源:h20564.www2.hp.com
链接:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04311273
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21674937
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21674428
来源:www-304.ibm.com
链接:https://www-304.ibm.com/support/docview.wss?uid=swg21674435
来源:kb.juniper.net
链接:http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10643&cat=SIRT_1&actp=LIST
来源:www.liferay.com
来源:DEBIAN
链接:https://www.debian.org/security/2014/dsa-2940
来源:MLIST
来源:CONFIRM
链接:http://www.ibm.com/support/docview.wss?uid=swg21675496
来源:CONFIRM
链接:http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
来源:MISC
来源:MLIST
来源:HP
链接:http://marc.info/?l=bugtraq&m=140801096002766&w=2
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20180629-0006/
来源:MLIST
来源:MLIST
来源:CONFIRM
链接:https://www.vmware.com/security/advisories/VMSA-2014-0008.html
来源:CONFIRM
链接:https://access.redhat.com/solutions/869353
来源:MISC
来源:MLIST
来源:CONFIRM
链接:http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
来源:www-01.ibm.com
链接:https://www-01.ibm.com/support/docview.wss?uid=ibm10795183
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10872142
来源:issues.apache.org
链接:https://issues.apache.org/jira/browse/BEANUTILS-520
来源:www.mail-archive.com
链接:https://www.mail-archive.com/announce@apache.org/msg05413.html
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10887121
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10957873
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10887119
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10887113
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10888007
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10887999
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10887973
来源:www.ibm.com
链接:https://www.ibm.com/support/docview.wss?uid=ibm10888009
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75922
来源:www.ibm.com
来源:www.ibm.com
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2568/
来源:www.ibm.com
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1427/
来源:www.ibm.com
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2355/
来源:us-cert.cisa.gov
链接:https://us-cert.cisa.gov/ics/advisories/icsma-20-184-01
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/67121
来源:www.ibm.com
来源:www.ibm.com
来源:www.ibm.com
来源:www.ibm.com
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2293.2/
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10879093
来源:www-01.ibm.com
链接:https://www-01.ibm.com/support/docview.wss?uid=ibm10872142
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/78218
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.3134/
来源:www.ibm.com