SuSE: 2014:0902-1: important: struts
Summary
Apache Struts was updated to fix a security issue:
* CVE-2014-0114: The ActionForm object in Apache Struts 1.x through
1.3.10 allows remote attackers to "manipulate" the ClassLoader and
execute arbitrary code via the class parameter, which is passed to
the getClass method.
Security Issue reference:
* CVE-2014-0114
References
#875455
Cross- CVE-2014-0114
Affected Products:
SUSE Manager Server
SUSE Manager 1.7 for SLE 11 SP2
SUSE Linux Enterprise Software Development Kit 11 SP3
https://www.suse.com/security/cve/CVE-2014-0114.html
https://bugzilla.novell.com/875455
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/