Hackers Actively Exploiting Patched Apache Struts Bug in Corporate Web Servers

By Marcos Colon

According to researchers at Qualys, a recently patched vulnerability in the open-source web development framework for Java web applications is being leveraged by attackers to fully compromise systems.

Impacting the framework’s multipart parser, the vulnerability allows for a cyber criminal to “remotely and without need of any credentials take complete control of the system,” according to a blog post by Amol Sarwate, director of Vulnerability Labs at Qualys.

Although the flaw was addressed on March 6, researchers from Cisco Systems have shared with CSO Online that real-world attacks leveraging the vulnerability took place hours after it was patched.

Used to build corporate websites in the education, government, and financial services sectors, companies that use Apache Struts on their servers should upgrade to versions 2.3.32 or as soon as possible. 

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.