Vulnerability Description
Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensymphony | Xwork | < 1.2.3 |
References
- http://forums.opensymphony.com/ann.jspa?annID=54PatchVendor Advisory
- http://issues.apache.org/struts/browse/WW-2030Third Party Advisory
- http://jira.opensymphony.com/browse/XW-544Vendor Advisory
- http://jira.opensymphony.com/secure/ReleaseNote.jspa?projectId=10050&styleName=HVendor Advisory
- http://jira.opensymphony.com/secure/ReleaseNote.jspa?projectId=10050&styleName=HVendor Advisory
- http://osvdb.org/37072Broken Link
- http://secunia.com/advisories/26681Third Party Advisory
- http://secunia.com/advisories/26693Third Party Advisory
- http://secunia.com/advisories/26694Third Party Advisory
- http://struts.apache.org/2.x/docs/s2-001.htmlPatchThird Party Advisory
- http://wiki.opensymphony.com/display/WW/1.2.3+Press+ReleaseVendor Advisory
- http://www.securityfocus.com/bid/25524Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2007/3041Third Party Advisory
- http://www.vupen.com/english/advisories/2007/3042Third Party Advisory
- http://forums.opensymphony.com/ann.jspa?annID=54PatchVendor Advisory
FAQ
What is CVE-2007-4556?
CVE-2007-4556 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression ...
How severe is CVE-2007-4556?
CVE-2007-4556 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4556?
Check the references section above for vendor advisories and patch information. Affected products include: Opensymphony Xwork.