Vulnerable Systems:
* Apache Software Foundation Struts 2.2.3 and prior
Attackers can exploit this issue to manipulate server-side context objects with the privileges of the user running the application. Successful exploits can compromise the application and possibly the underlying computer.
This issue is related to the vulnerability documented in BID 32101(XWork 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability).
Apache Struts versions 2.0.0 through 2.3.1.1 are vulnerable.
Vendor Status:
Apache Software Foundation as issued an update for this vulnerablity.