{"id":4115,"date":"2014-11-04T21:41:27","date_gmt":"2014-11-04T12:41:27","guid":{"rendered":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/?p=4115"},"modified":"2022-06-13T15:38:05","modified_gmt":"2022-06-13T06:38:05","slug":"struts%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ae%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6%e7%9f%a5%e3%82%8a%e3%81%9f%e3%81%84%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/?p=4115","title":{"rendered":"Struts\u306e\u8106\u5f31\u6027\u306e\u5bfe\u5fdc\u306b\u3064\u3044\u3066\u77e5\u308a\u305f\u3044\u3002"},"content":{"rendered":"<h2>\u8981\u671b<\/h2>\n<p>Struts\u306e\u4ee5\u4e0b\u306e\u8106\u5f31\u6027\u306e\u5bfe\u5fdc\u306b\u3064\u3044\u3066\u77e5\u308a\u305f\u3044\u3002<\/p>\n<p>CVE-2014-0050 DoS<br \/>\nCVE-2014-0094,CVE-2-14-0114 ClassLoader manipulation<br \/>\nCVE-2014-0112 Incomplete fix for ClassLoader manipulation via ParametersInterceptor<br \/>\nCVE-2014-0113 ClassLoader manipulation via CookieInterceptor when configured to accept all cookies<\/p>\n<p>S2-037: Remote Code Execution can be performed when using REST Plugin.<br \/>\n<a href=\"https:\/\/struts.apache.org\/docs\/s2-037.html\">https:\/\/struts.apache.org\/docs\/s2-037.html<\/a><\/p>\n<h2>\u89e3\u8aac<\/h2>\n<p>OpManager\u306fStruts ver1.0\u3092\u4f7f\u7528\u3057\u3066\u304a\u308a\u307e\u3059\u3002<br \/>\n\u305d\u306e\u305f\u3081Struts ver2.0,\u3067\u767a\u751f\u3059\u308bCVE-2014-0094,CVE-2014-0112\u3001CVE-2014-0113\u306f\u8a72\u5f53\u3057\u307e\u305b\u3093\u3002<br \/>\nCVE-2014-0050,CVE-2-14-0114\u306f\u3001OpManager ver11.4\u3067\u5bfe\u5fdc\u81f4\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>S2-037\u306fStruts 2\u306eREST plugin\u306b\u95a2\u3059\u308b\u8106\u5f31\u6027\u3068\u306a\u308a\u3001\u672c\u30d7\u30e9\u30b0\u30a4\u30f3\u306fStruts 1.1\u3067\u306f\u975e\u30b5\u30dd\u30fc\u30c8\u3068\u306a\u308a\u307e\u3059\u3002<br \/>\nOpManager 11.6\u3067\u306f\u672c\u30d7\u30e9\u30b0\u30a4\u30f3\u306f\u4f7f\u7528\u3057\u3066\u3044\u306a\u3044\u305f\u3081\u3001\u672c\u8106\u5f31\u6027\u306b\u306f\u8a72\u5f53\u3057\u307e\u305b\u3093\u3002<\/p>\n<p>\u3010\u5bfe\u5fdc\u30ea\u30ea\u30fc\u30b9\u3011 11400\u4ee5\u4e0a<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8981\u671b Struts\u306e\u4ee5\u4e0b\u306e\u8106\u5f31\u6027\u306e\u5bfe\u5fdc\u306b\u3064\u3044\u3066\u77e5\u308a\u305f\u3044\u3002 CVE-2014-0050 DoS CVE-2014-0094,CVE-2-14-0114 \u2026 <a href=\"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/?p=4115\" class=\"more\">\uff3b\u7d9a\u304d\u3092\u8aad\u3080\uff3d<\/a><\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"yes","_lmt_disable":"","footnotes":""},"categories":[15],"tags":[1012],"class_list":["post-4115","post","type-post","status-publish","format-standard","hentry","category-7-trouble-opm","tag-1012"],"modified_by":"yuka","_links":{"self":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=\/wp\/v2\/posts\/4115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4115"}],"version-history":[{"count":6,"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=\/wp\/v2\/posts\/4115\/revisions"}],"predecessor-version":[{"id":19389,"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=\/wp\/v2\/posts\/4115\/revisions\/19389"}],"wp:attachment":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/OpManager\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}