1
Candidate: CVE-2014-0094
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0094
5
https://cwiki.apache.org/confluence/display/WW/S2-020
7
The ParametersInterceptor in Apache Struts before 2.3.16.1 allows remote
8
attackers to "manipulate" the ClassLoader via the class parameter, which is
9
passed to the getClass method.
13
https://bugzilla.redhat.com/show_bug.cgi?id=1073716
15
Discovered-by: Peter Magnusson, Przemysław Celj
18
Patches_libstruts1.2-java:
19
upstream_libstruts1.2-java: released (2.3.16.1)
20
lucid_libstruts1.2-java: not-affected
21
precise_libstruts1.2-java: not-affected
22
quantal_libstruts1.2-java: not-affected
23
saucy_libstruts1.2-java: not-affected
24
devel_libstruts1.2-java: not-affected