Boletines de Vulnerabilidades

Apache Struts Vulnerability Affecting Cisco Products: December 2023


Información sobre el sistema

   
Software afectado Cisco

Descripción

On December 7, 2023, the following vulnerability in Apache Struts was disclosed: CVE-2023-50164: An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. For a description of this vulnerability, see the Apache Software Foundation Security Bulletin. This advisory is available at the following link:

More info:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-struts-C2kCMkmT?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Apache%20Struts%20Vulnerability%20Affecting%20Cisco%20Products:%20December%202023&vs_k=1

Identificadores estándar

Propiedad Valor
CVE CVE-2023-50164.

Histórico de versiones

Versión Comentario Fecha

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT