Apache Continuum Remote Code Execution

Strike ID:
E16-z6701
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2016

Description

This strike exploits a vulnerability in Apache Continuum. Specifically in versions 1.4.2 and prior, due to the lack of sanitization of user input, it is possible to inject code into the installation.varValue parameter of an HTTP request to the continuum/saveInstallation.action URI. This type of code injection can lead to remote code execution on the target system.