Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2014-0094

MEDIUM · 5.0 CVSS Gepubliceerd:

Beschrijving NL

Met de ParametersInterceptor in Apache Struts vóór 2.3.16.2 kunnen externe aanvallers de ClassLoader "manipuleren" via de klasseparameter, die wordt doorgegeven aan de getClass-methode.

Origineel (Engels) tonen

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

Vendors

Apache

Affected products

Struts

References