ENISA EUVD · EUVD-2024-3418Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2024-3660Apache Struts: Schwachstelle ermöglicht CodeausführungEin entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Struts ausnutzen, um beliebigen Programmcode auszuführen.
Official advisory ↗BSI · German · WID-SEC-2025-1479SAP Patchday Juli 2025: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in SAP Software ausnutzen, um erhöhte Berechtigungen zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht spezifizierte Auswirkungen zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2025-0148Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗Canadian Centre for Cyber Security · English · AL24-013CVE-2024-53677 - Vulnerability impacting Apache Struts 2An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
Official advisory ↗Canadian Centre for Cyber Security · English · AV24-708Apache security advisory (AV24-708)On November 26, 2024, Apache published a security advisory to address a critical vulnerability (CVE-2024-53677) in the following products:
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20241218Security Bulletin 18 Dec 2024The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 18 Dec 2024, published on 18 December 2024. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0564Multiples vulnérabilités dans les produits SAPversions SAP_CAR 7.53 et 7.22EXT
Supplier Relationship Management (Live Auction Cockpit) version SRM_SERVER 7.14
Résumé
De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité SAP july-2025 du 08 juillet 2025
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2025.html
Référence CVE CVE-2024-53677
https://www.cve.org/CVERecord?id=CVE-2024-53677
Référence CVE CVE-2025-30009
https://www.cve.org/CVERecord?id=CVE-2025-30009
Référence CVE CVE-2025-30010
https://www.cve.org/CVERecord?id=CVE-2025-30010
Référence CVE CVE-2025-30011
https://www.cve.org/CVERecord?id=CVE-2025-30011
Référence CVE CVE-2025-30012
https://www.cve.org/CVERecord?id=CVE-2025-30012
Référence CVE CVE-2025-30018
https://www.cve.org/CVERecord?id=CVE-2025-30018
Référence CVE CVE-2025-31326
https://www.cve.org/CVERecord?id=CVE-2025-31326
Référence CVE CVE-2025-42952
https://www.cve.org/CVERecord?id=CVE-2025-42952
Référence CVE CVE-2025-42953
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0401Multiples vulnérabilités dans Juniper Networks Secure Analyticsd?id=CVE-2024-45770
Référence CVE CVE-2024-46826
https://www.cve.org/CVERecord?id=CVE-2024-46826
Référence CVE CVE-2024-47668
https://www.cve.org/CVERecord?id=CVE-2024-47668
Référence CVE CVE-2024-50302
https://www.cve.org/CVERecord?id=CVE-2024-50302
Référence CVE CVE-2024-50379
https://www.cve.org/CVERecord?id=CVE-2024-50379
Référence CVE CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
Référence CVE CVE-2024-52337
https://www.cve.org/CVERecord?id=CVE-2024-52337
Référence CVE CVE-2024-53104
https://www.cve.org/CVERecord?id=CVE-2024-53104
Référence CVE CVE-2024-53197
https://www.cve.org/CVERecord?id=CVE-2024-53197
Référence CVE CVE-2024-53677
https://www.cve.org/CVERecord?id=CVE-2024-53677
Référence CVE CVE-2024-56171
https://www.cve.org/CVERecord?id=CVE-2024-56171
Référence CVE CVE-2024-56326
https://www.cve.org/CVERecord?id=CVE-2024-56326
Référence CVE CVE-2024-56337
https://www.cve.org/CVERecord?id=CVE-2024-56337
Référence CVE CVE-2024-56463
https://www.cve.org/CVERecord?id=CVE-2024-56463
Référence CVE CVE-2024-57807
https://www.cve.org/CVERecord?id=CVE-2024-57807
Référence CVE CVE-2024-57979
https://www.cve.org/CVERecord?id=CVE-2024-57979
Référence CVE CVE-2024-7348
https://www.cve.org/CVERecord?id=CVE-2024-7348
Référence CVE CVE-2024-8508
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0106Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-50268
Référence CVE CVE-2024-50274
https://www.cve.org/CVERecord?id=CVE-2024-50274
Référence CVE CVE-2024-50275
https://www.cve.org/CVERecord?id=CVE-2024-50275
Référence CVE CVE-2024-50279
https://www.cve.org/CVERecord?id=CVE-2024-50279
Référence CVE CVE-2024-50282
https://www.cve.org/CVERecord?id=CVE-2024-50282
Référence CVE CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
Référence CVE CVE-2024-53047
https://www.cve.org/CVERecord?id=CVE-2024-53047
Référence CVE CVE-2024-53064
https://www.cve.org/CVERecord?id=CVE-2024-53064
Référence CVE CVE-2024-53140
https://www.cve.org/CVERecord?id=CVE-2024-53140
Référence CVE CVE-2024-53677
https://www.cve.org/CVERecord?id=CVE-2024-53677
Référence CVE CVE-2024-5569
https://www.cve.org/CVERecord?id=CVE-2024-5569
Référence CVE CVE-2024-56201
https://www.cve.org/CVERecord?id=CVE-2024-56201
Référence CVE CVE-2024-56326
https://www.cve.org/CVERecord?id=CVE-2024-56326
Référence CVE CVE-2024-7348
https://www.cve.org/CVERecord?id=CVE-2024-7348
Gestion détaillée du document
le 07 février 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-1066Vulnérabilité dans Apache StrutsUne vulnérabilité a été découverte dans Apache Struts. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2024-014619Apache Struts 2 のファイルアップロード処理に不備(S2-067)The Apache Software Foundation が提供する Apache Struts 2 には、ファイルアップロード処理に不備(CVE-2024-53677)が存在します。ファイルアップロード時のパラメータが細工された場合、悪意のあるファイルをアップロードされる可能性があります。 開発者は本脆弱性を S2-066( JVNVU#96961218 で公表)と同様の問題と報告しています。 なお、File Upload Interceptor を使用していない場合、本脆弱性の影響は受けません。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-6356Apache 제품 보안 업데이트 권고Apache Struts에서 발생하는 원격 코드 실행 취약점(CVE-2024-53677) [1][2]
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0219Kwetsbaarheden verholpen in SAP productenDe kwetsbaarheden omvatten onder andere remote code execution, code injectie, en insecure deserialization, die door aanvallers met gebruikersprivileges kunnen worden misbruikt om schadelijke code te creëren of uit te voeren. Dit kan leiden tot ernstige bedreigingen voor de vertrouwelijkheid, integriteit en beschikbaarheid van de getroffen systemen. Specifieke kwetsbaarheden zoals een replay-aanval en privilege-escalatie zijn ook geïdentificeerd, wat de noodzaak benadrukt voor strikte autorisatiecontroles en monitoring van de systemen. De impact varieert van ongeautoriseerde toegang tot gegevens tot volledige systeemcompromittering.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0021Kwetsbaarheden verholpen in Oracle CommunicationsDe kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om Denial of Service (DoS) aanvallen uit te voeren of om ongeautoriseerde toegang tot gevoelige gegevens te verkrijgen. Specifieke versies, zoals 24.2.0 en 24.3.0 van de Cloud Native Core Network Function, zijn bijzonder kwetsbaar. Kwaadwillenden kunnen deze kwetsbaarheden misbruiken door speciaal geprepareerde HTTP-verzoeken te sturen naar het kwetsbare systeem.
Official advisory ↗NCSC-NL · Dutch · NCSC-2024-0492Kwetsbaarheid verholpen in Apache StrutsDe kwetsbaarheid bevindt zich in de wijze waarop de bestandupload logica is geïmplementeerd in de verouderde **FileUploadInterceptor**. Deze kwetsbaarheid kan worden misbruikt om willekeurige code op systemen die deze versies draaien uit te voeren. Aangezien de getroffen versies veelvuldig worden gebruikt in verschillende applicaties, kan de impact aanzienlijk zijn.
Applicaties die gebruik maken van het vernieuwde **ActionFileUploadInterceptor** zijn niet gevoelig voor misbruik.
Official advisory ↗