SUSE-SU-2015:0886-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0886-1
SUSE-SU-2015:0886-1
Summary: Security update for struts
Details: Apache Struts was updated to fix a security issue: * CVE-2014-0114: The ActionForm object in Apache Struts 1.x through 1.3.10 allows remote attackers to 'manipulate' the ClassLoader and execute arbitrary code via the class parameter, which is passed to the getClass method. Security Issue reference: * CVE-2014-0114 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0114>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150886-1/, https://bugzilla.suse.com/875455, https://bugzilla.suse.com/924887, https://www.suse.com/security/cve/CVE-2014-0114, https://www.suse.com/security/cve/CVE-2015-0899
