-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


- Apache Struts

, 13 2017 . 11:48 +
ptsecurity 11:48

- Apache Struts



    - Apache Struts , .

    Apache Software Foundation , Cisco , .


    Freemarker Apache Struts 2. Freemarker Template Language , Apache Struts Java. , , .

    Object Graph Navigation Language (OGNL), .

    Cisco:

    • Cisco Digital Media Manager , 19 2016 ;
    • Cisco Hosted Collaboration Solution for Contact Center;
    • Cisco Unified Contact Center Enterprise;
    • Cisco Unified Intelligent Contact Management Enterprise.

    20 , , .

    Cisco: Equifax


    CVE-2017-12611 (S2-053), Apache Struts , CVE-2017-9805 (S2-052), CVE-2017-9791 (S2-048) CVE-2017-5638 (S2-045). , Equifax Apache Struts.

    Positive Technologies - , , . , .

    , Equifax .



    XSS Equifax, : ZDNet

    Equifax Apache Struts , - , . , , WAF ( PT Application Firewall).


    , CVE-2017-12611 Cisco, , . Freemarker read-only , .

    , Positive Technologies Apache Struts 2.5.12 2.3.34, Freemarker. .
    Original source: habrahabr.ru (comments, light).

    https://habrahabr.ru/post/337760/

    :  

    : [1] []
     

    :
    : 

    : ( )

    :

      URL