{"affected":[],"aliases":[],"details":"\nApache Struts was updated to fix a security issue:\n\n    * CVE-2014-0114: The ActionForm object in Apache Struts 1.x through\n      1.3.10 allows remote attackers to 'manipulate' the ClassLoader and\n      execute arbitrary code via the class parameter, which is passed to\n      the getClass method.\n\nSecurity Issue reference:\n\n    * CVE-2014-0114\n      <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0114>\n\n","id":"SUSE-SU-2015:0886-1","modified":"2014-06-20T20:43:07Z","published":"2014-06-20T20:43:07Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150886-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/875455"},{"type":"REPORT","url":"https://bugzilla.suse.com/924887"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-0114"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0899"}],"related":["CVE-2014-0114","CVE-2015-0899"],"summary":"Security update for struts","upstream":["CVE-2014-0114","CVE-2015-0899"]}