Apache Struts 2 Demo Application Detected

low Web App Scanning Plugin ID 112760

Synopsis

Apache Struts 2 Demo Application Detected

Description

The scanner has detected a publicly accessible Apache Struts 2 default demo application.

Known and unknown vulnerabilities could be more easily exploited via this kind of application.

Solution

Delete the demo application or restrict access using a .htaccess file, limiting access to known IP Addresses.

Plugin Details

Severity: Low

ID: 112760

Type: remote

Published: 4/23/2021

Updated: 9/7/2021

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Low

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Low

Base Score: 3.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*

Reference Information