5
CVSSv2

CVE-2017-15707

Published: 01/12/2017 Updated: 26/04/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.2 | Impact Score: 3.6 | Exploitability Score: 2.5
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts

netapp oncommand balance -

oracle retail xstore point of service 7.1.6

oracle retail xstore point of service 15.0.1

oracle retail xstore point of service 16.0.2

oracle jd edwards enterpriseone tools 9.2

oracle weblogic server 12.2.1.3

oracle enterprise manager for virtualization 13.2.3

oracle agile plm framework 9.3.6

oracle retail xstore point of service 6.5.11

oracle webcenter portal 12.2.1.3.0

oracle global lifecycle management opatchauto

oracle financial services hedge management and ifrs valuations 8.0.4

oracle financial services hedge management and ifrs valuations 8.0.5

oracle financial services market risk measurement and management 8.0.5

oracle weblogic server 12.2.1.2

oracle enterprise manager for virtualization 13.2.2

oracle retail order broker 5.2

oracle retail xstore point of service 7.0.6

oracle webcenter portal 12.2.1.2.0

Vendor Advisories

In Apache Struts 25 to 2514, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload ...