Critical Apache flaw 'puts over 50% of Fortune 100 at risk'

Researchers discover remote code execution vulnerability in Apache Struts framework

Open Source

More than half of the Fortune 100 could be at risk from a security flaw affecting the Apache Struts development framework, researchers have warned.

The critical vulnerability affects all versions of Apache Struts released since 2008, and leaves any server running the widely-implemented REST communication plugin open to remote code execution.

Advertisement - Article continues below

The flaw was discovered by researchers from lgtm, an open source software engineering analytics firm. "The lgtm security team have a simple working exploit for this vulnerability which will not be published at this stage," wrote Bas Van Schaik, product manager of lgmt parent company Semmle as part of a blog post announcing the vulnerability.

"At the time of the announcement there is no suggestion that an exploit is publicly available, but it is likely that there will be one soon."

The Apache Software Foundation has patched the vulnerability in Struts version 2.5.13, and any organisations using older versions are being urged to update as a matter of some urgency.

The open source software is widely used by many companies to develop their applications, with businesses like Citigroup, Virgin Atlantic and Lockheed Martin confirmed as users. In fact, RedMonk analyst Fintan Ryan pegged the number of Fortune 100 companies using Struts-based apps at at least 65%.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"This vulnerability poses a huge risk, because the framework is typically used for designing publicly-accessible web applications," said Man Yue Mo, one of the researchers who discovered the flaw. "Struts is used in several airline booking systems as well as a number of financial institutions who use it in internet banking applications. On top of that, it is incredibly easy for an attacker to exploit this weakness: all you need is a web browser."

"This is as serious as it gets," said Semmle founder Oege de Moor. "If remote attackers are allowed to exploit the newly identified vulnerability it can critically damage thousands of enterprises.

"In the spirit of open source, we want to make sure that the community and industry are aware of these findings as we help uncover critical issues in large numbers of open-source projects. Working with Apache Struts, they were extremely responsive and immediately came up with a clear remediation path."

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/security/hacking/355774/nigerian-hackers-swindle-millions-of-dollars-from-unemployment-systems
hacking

Nigerian hackers swindle millions of dollars from unemployment systems

22 May 2020
Visit/security/hacking/355773/hackers-take-on-unsuspecting-airliners-exposing-customer-data
hacking

Hackers take on unsuspecting airliners, exposing customer data

22 May 2020
Visit/security/hacking/355749/hackers-targets-game-developers-with-advanced-malware
hacking

Hackers target game developers with advanced malware

21 May 2020
Visit/security/hacking/355738/security-service-of-ukraine-arrests-infamous-hacker-sanix
hacking

Security Service of Ukraine arrests infamous hacker Sanix

21 May 2020

Most Popular

Visit/mobile/5g/355712/nokia-5g-speed-record
5G

Nokia breaks 5G record with speeds nearing 5Gbps

20 May 2020
Visit/cloud/cloud-computing/355742/microsoft-launches-public-cloud-service-for-health-care
cloud computing

Microsoft launches public cloud service for health care

21 May 2020
Visit/software/video-conferencing/355596/house-of-commons-to-ditch-zoom
video conferencing

House of Commons to ditch Zoom in favour of British alternative

11 May 2020