The REST Plugin in Apache Struts 2.1.x, 2.3.7 up to and including 2.3.33 and 2.5 up to and including 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apache struts 2.5.10.1 |
||
apache struts 2.3.12 |
||
apache struts 2.3.13 |
||
apache struts 2.3.15.2 |
||
apache struts 2.3.15.3 |
||
apache struts 2.3.16 |
||
apache struts 2.3.20.1 |
||
apache struts 2.3.20.2 |
||
apache struts 2.3.26 |
||
apache struts 2.3.27 |
||
apache struts 2.5 |
||
apache struts 2.5.5 |
||
apache struts 2.5.6 |
||
apache struts 2.3.8 |
||
apache struts 2.3.9 |
||
apache struts 2.3.14.2 |
||
apache struts 2.3.14.3 |
||
apache struts 2.3.16.3 |
||
apache struts 2.3.17 |
||
apache struts 2.3.23 |
||
apache struts 2.3.24.2 |
||
apache struts 2.3.29 |
||
apache struts 2.3.30 |
||
apache struts 2.5.1 |
||
apache struts 2.5.2 |
||
apache struts 2.5.9 |
||
apache struts 2.5.10 |
||
apache struts 2.5.12 |
||
apache struts 2.3.7 |
||
apache struts 2.3.14 |
||
apache struts 2.3.14.1 |
||
apache struts 2.3.16.1 |
||
apache struts 2.3.16.2 |
||
apache struts 2.3.21 |
||
apache struts 2.3.22 |
||
apache struts 2.3.28 |
||
apache struts 2.3.28.1 |
||
apache struts 2.5.7 |
||
apache struts 2.5.8 |
||
apache struts 2.3.10 |
||
apache struts 2.3.11 |
||
apache struts 2.3.15 |
||
apache struts 2.3.15.1 |
||
apache struts 2.3.19 |
||
apache struts 2.3.20 |
||
apache struts 2.3.24.3 |
||
apache struts 2.3.25 |
||
apache struts 2.3.31 |
||
apache struts 2.3.32 |
||
apache struts 2.3.33 |
||
apache struts 2.5.3 |
||
apache struts 2.5.4 |
Big Red issues out-of-band patch for Apache and a few other urgent issues
Oracle has stepped outside its usual quarterly security fix cycle to address the latest Apache Struts 2 vulnerability. Ever since it emerged at the start of September, CVE-2017-9805 has been (in the words of a former Australian prime minister) “a shiver looking for a spine to crawl up”, because so many vendors use Apache to build Web interfaces and bake Struts 2 into their their Web application framework. Big Red's sprawling product set meant fixes had to be deployed across more than 20 prod...