Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le septembre 21, 2017, 19:00:10

Titre: [Trend]a-PATCH-e: Struts Vulnerabilities Run Rampant
Posté par: igor51 le septembre 21, 2017, 19:00:10
a-PATCH-e: Struts Vulnerabilities Run Rampant

Equifax confirmed the attack vector used in its data breach to be CVE-2017-5638, a vulnerability patched last March 2017 via S2-045. The vulnerability was exploited to gain unauthorized access to highly sensitive data of approximately 143 million U.S. and 400,000 U.K. customers, as well as 100,000 Canadian consumers. This vulnerability was first disclosed in March, almost immediately followed by publicly available POCs, weaponized exploits, and scanners produced by third parties.


Trend Micro observed thousands of filter events via our intrusion prevention solutions against the filters for this vulnerability since March, and these exploits or enumeration attempts are still being seen. It’s worth noting that these solutions can leverage these filters to provide a highly effective virtual patch to address critical Apache Struts vulnerabilities until actual software updates are deployed to secu


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


a-PATCH-e: Struts Vulnerabilities Run Rampant


Source: a-PATCH-e: Struts Vulnerabilities Run Rampant (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/EOST6qas4Mc/)