CVE-2017-15707
6.2
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.5 / Impact: 3.6
Source: NVD
Description
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
Affected (20)
Products: Apache: Struts · Netapp: Oncommand Balance · Oracle: Agile Plm Framework, Enterprise Manager For Virtualization, Financial Services Hedge Management And Ifrs Valuations, Financial Services Market Risk Measurement And Management, Global Lifecycle Management Opatchauto, Jd Edwards Enterpriseone Tools, Retail Order Broker, Retail Xstore Point Of Service, Webcenter Portal, Weblogic Server
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.3.6 | |
| Version 13.2.2 | |
| Version 8.0.4 | |
| Version 8.0.5 | |
| All versions | |
| Version 9.2 | |
| Version 5.2 | |
| Version 15.0.1 | |
| Version 12.2.1.2.0 | |
| Version 12.2.1.2 |
References (12)
Source: security@apache.org
Patch
Source: security@apache.org
Patch
Source: security@apache.org
PatchVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.