← All CVEs

CVE-2018-11776

high · 8.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

8.1
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2018-08-22
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
apachestruts>= 2.0.4, < 2.3.35
apachestruts>= 2.5.0, < 2.5.17
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
netapponcommand_insightall versions
netapponcommand_workflow_automationall versions
netappsnapcenterall versions
oraclecommunications_policy_management< 12.5.0
oracleenterprise_manager_base_platform13.3.0.0
oracleenterprise_manager_base_platform13.4.0.0
oraclemysql_enterprise_monitor<= 3.4.9.4237
oraclemysql_enterprise_monitor>= 4.0.0, <= 4.0.6.5281
oraclemysql_enterprise_monitor>= 8.0.0, <= 8.0.2.8191

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-11776