VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago

CVE-2018-11776

8.1 High Protected by RASP

Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

CWE-20 · Improper input validation

Exploitation Status

Exploited in the wild

Confirmed real-world exploitation.

CVSS E:A

  • CISA KEV listed Confirmed exploitation in the wild. Added 2021-11-03 · remediation due 2022-05-03 · ransomware use: unknown
  • CISA Vulnrichment exploitation: active CISA records active exploitation. Automatable: no, technical impact: total.
  • Indexed PoC 20 indexed Published artifacts you can open, in Exploit-DB, GitHub PoC, Nuclei; first seen 2018-08-23.
  • EPSS 99.9% chance in 30 days A model prediction, not an observation. Higher than 99.9% of all scored CVEs.
IndexArtifactStarsFirst seen
GitHub PoC An exploit for Apache Struts CVE-2018-11776 303 2018-08-25
Nuclei Apache Struts2 S2-057 - Remote Code Execution
Exploit-DB Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit) 2018-09-10
GitHub PoC Working Python test and PoC for CVE-2018-11776, includes Docker lab 123 2018-08-24
Exploit-DB Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit) 2018-09-10
GitHub PoC This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers. 56 2018-08-29
Exploit-DB Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1) 2018-08-26
GitHub PoC Proof of Concept for CVE-2018-11776 21 2018-08-27
Exploit-DB Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2) 2018-08-25
GitHub PoC Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts. 17 2019-10-10

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: Manual classification assigned status: MITIGATED-BY-SECURE-RULE

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification assigned status: MITIGATED-BY-SECURE-RULE

CVSS

8.1 HIGH v3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H NVD Primary published
CVSS 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CISA-ADP Secondary
CVSS 2.0 9.3 no band published AV:N/AC:M/Au:N/C:C/I:C/A:C NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update July 2020 CPU 2020-Q3 Oracle Enterprise Manager / Reporting Framework (Apache Struts 2) (13.3.0.0, 13.4.0.0)
Oracle Critical Patch Update January 2019 CPU 2019-Q1 Oracle Communications Applications / Security (Apache Struts 2) (prior to 12.5)
Oracle Critical Patch Update October 2018 CPU 2018-Q4 Oracle MySQL / Monitoring: General (Apache Struts 2) (3.4.9.4237 and prior, 4.0.6.5281 and prior, 8.0.2.8191 and prior)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Communications Applications Security (Apache Struts 2) prior to 12.5
Oracle Enterprise Manager Reporting Framework (Apache Struts 2) 13.3.0.0, 13.4.0.0 13.3.0.0 · 13.4.0.0
Oracle MySQL Monitoring: General (Apache Struts 2) 3.4.9.4237 and prior, 4.0.6.5281 and prior, 8.0.2.8191 and prior

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.apache.struts:struts2-core 2.0.4 2.3.35 unbounded
org.apache.struts:struts2-core 2.5 2.5.17 unbounded

🖥️ Product CPEs & Version Ranges

9 product(s) over 15 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apache struts generic ≥ 2.0.4 and < 2.3.35 · ≥ 2.5.0 and < 2.5.17
nvd netapp active iq unified manager generic ≥ 7.3 · ≥ 9.5
nvd netapp oncommand insight generic any version
nvd netapp oncommand workflow automation generic any version
nvd netapp snapcenter generic any version
nvd oracle communications policy management generic < 12.5.0
nvd oracle enterprise manager base platform generic 13.3.0.0 · 13.4.0.0
nvd oracle mysql enterprise monitor generic ≤ 3.4.9.4237 · ≥ 4.0.0 and ≤ 4.0.6.5281 · ≥ 8.0.0 and ≤ 8.0.2.8191
osv org.apache.struts struts2-core generic ≥ 2.0.4 and < 2.3.35 · ≥ 2.5 and < 2.5.17

Manual classification context

A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.

## Manual Classification Context **Labels:** HTTP, SECURITY (APACHE STRUTS 2), REPORTING FRAMEWORK (APACHE STRUTS 2), NO AUTH REMOTE EXPLOIT, MONITORING: GENERAL (APACHE STRUTS 2) **Products:** APACHE STRUTS 2

References

URLTags
https://github.com/apache/struts/commit/6e87474f9ad0549f07dd2c37d50a9ccd0977c6e WEB
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html WEB
https://www.oracle.com/security-alerts/cpujul2020.html WEB
https://www.exploit-db.com/exploits/45367 WEB
https://www.exploit-db.com/exploits/45262 WEB
https://www.exploit-db.com/exploits/45260 WEB
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776 WEB
https://web.archive.org/web/20201208145803/https://securitytracker.com/id/1041547 WEB
https://web.archive.org/web/20200807025819/http://www.securitytracker.com/id/1041888 WEB
https://web.archive.org/web/20180822160726/http://www.securityfocus.com/bid/105125 WEB

Timeline

Published 2018-08-22 Last modified 2026-06-17
Published2018-08-22By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.