Published:2014/06/17  Last Updated:2014/06/17

Information from NTT DATA Corporation

Vulnerability ID:JVN#30962312
Title:TERASOLUNA Server Framework for Java(Web) vulnerable to ClassLoader manipulation
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

We provide information on this issue at the following URL.

NTT DATA Corporation - News Center
http://www.nttdata.com/global/en/news-center/others/2014/052300.html

TERASOLUNA Framework
http://en.sourceforge.jp/projects/terasoluna/

Apache Struts 1.2.9 with SP1 by NTT DATA
http://en.sourceforge.jp/projects/terasoluna/wiki/StrutsPatch1-EN