imPC@ndo IT

Tracker / CVE-2013-4316

CVE-2013-4316

High 10.0

Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.

Affected products and versions

apache struts
oracle flexcube_private_banking
oracle mysql_enterprise_monitor · … → 2.3.14
oracle mysql_enterprise_monitor · … → 3.0.4
oracle webcenter_sites

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References