CVE-2014-0114
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
- Affected products
- Apache Commons Beanutils, Apache Struts, Oracle Weblogic Server, Red Hat, Suse, Ubuntu, Vmware Vcenter
- Apache Commons Beanutils
- ≤ 1.9.1
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 96.1% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2014-04-30
CVE-2014-0114 at NVD
5 known exploits for CVE-2014-0114
Proof-of-concept code and exploit modules indexed by Sploitus
OSCAR EMR 15.21beta361 XSS / Disclosure / CSRF / Insecure Direct Object Reference
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution Exploit
Apache Struts ClassLoader Manipulation Remote Code Execution
Apache Struts ClassLoader Manipulation Remote Code Execution
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)