Apache Struts 2.x < 220.127.116.11 Dynamic Method Invocation Multiple Vulnerabilities (S2-019)
Critical Nessus Plugin ID 117402
SynopsisA web application running on the remote host uses a Java framework that is affected by multiple Dynamic Invocation Method vulnerabilities.
DescriptionThe version of Apache Struts running on the remote host is 2.x prior to 18.104.22.168. It, therefore, is affected by multiple Dynamic Method Invocation (DMI) vulnerabilities as DMI is enabled by default.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Apache Struts version 22.214.171.124 or later or follow the vendors instructions to disable DMI.