Cisco's Talos team says 0-day being targeted affects Apache Struts, updates available Credit: Martyn Williams Cisco’s Talos says they’ve observed active attacks against a Zero-Day vulnerability in Apache’s Struts, a popular Java application framework. Cisco started investigating the vulnerability shortly after it was disclosed, and found a number of active attacks.In an advisory issued on Monday, Apache says the problem with Struts exists within the Jakarta Multipart parser.“It is possible to perform a RCE attack with a malicious Content-Type value. If the Content-Type value isn’t valid an exception is thrown which is then used to display an error message to a user,” the warning explained.“If you are using Jakarta based file upload Multipart parser, upgrade to Apache Struts version 2.3.32 or 2.5.10.1. You can also switch to a different implementation of the Multipart parser.” The alternative is the Pell parser plugin, which uses Jason Pell’s multipart parser instead of the Common-FileUpload library, Apache explains. More information can be found in their documentation.In addition, administrators concerned about the issue could just apply the proper updates, which are currently available. In a blog post, Cisco said they discovered a number of attacks that seem to be leveraging a publicly released proof-of-concept to run various commands. Such commands include simple ones (‘whoami’) as well as more sophisticated ones, including pulling down malicious ELF executable and running it.An example of one attack, which attempts to copy the file to a harmless directory, ensure the executable runs, and that the firewall is disabled is boot-up, is below: Both Cisco and Apache urge administrators to take action, either by patching or ensuring their systems are not vulnerable.This isn’t the first time the Struts platform has come under attack. In 2013, Chinese hackers were using an automated tool to exploit known vulnerabilities in order to install a backdoor. Related content news Gwinnett Medical Center investigating possible data breach After being contacted by Salted Hash, Gwinnett Medical Center has confirmed they're investigating a security incident By Steve Ragan Oct 02, 2018 6 mins Regulation Data Breach Hacking news Facebook: 30 million accounts impacted by security flaw (updated) In a blog post, Facebook’s VP of product management Guy Rosen said the attackers exploited a flaw in the website's 'View As' function By Steve Ragan Sep 28, 2018 4 mins Data Breach Security news Scammers pose as CNN's Wolf Blitzer, target security professionals Did they really think this would work? By Steve Ragan Sep 04, 2018 2 mins Phishing Social Engineering Security news Congress pushes MITRE to fix CVE program, suggests regular reviews and stable funding After a year of investigation into the Common Vulnerabilities and Exposures (CVE) program, the Energy and Commerce Committee has some suggestions as to how it can be improved By Steve Ragan Aug 27, 2018 3 mins Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe