Apache.Roller.OGNL.Injection.Remote.Code.Execution

description-logoDescription

This indicates a possible attack against a Command Execution vulnerability in Apache Roller.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. A remote attacker may exploit this by sending a specially crafted HTTP request to a vulnerable system. A successful attack may allow an attacker to execute arbitrary OGNL expressions in the security context of the web application server.

affected-products-logoAffected Products

Apache Software Foundation Apache Roller prior to 5.0.2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
http://rollerweblogger.org/project/entry/apache_roller_5_0_2

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-01-11 14.522 Sig Added