CVE-2017-15707

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
apachestruts
2.5 ≤
𝑥
≤ 2.5.14
netapponcommand_balance
-
oracleagile_plm_framework
9.3.6
oracleenterprise_manager_for_virtualization
13.2.2
oracleenterprise_manager_for_virtualization
13.2.3
oraclefinancial_services_hedge_management_and_ifrs_valuations
8.0.4
oraclefinancial_services_hedge_management_and_ifrs_valuations
8.0.5
oraclefinancial_services_market_risk_measurement_and_management
8.0.5
oracleglobal_lifecycle_management_opatchauto
*
oraclejd_edwards_enterpriseone_tools
9.2
oracleretail_order_broker
5.2
oracleretail_xstore_point_of_service
6.5.11
oracleretail_xstore_point_of_service
7.0.6
oracleretail_xstore_point_of_service
7.1.6
oracleretail_xstore_point_of_service
15.0.1
oracleretail_xstore_point_of_service
16.0.2
oraclewebcenter_portal
12.2.1.2.0
oraclewebcenter_portal
12.2.1.3.0
oracleweblogic_server
12.2.1.2
oracleweblogic_server
12.2.1.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libstruts1.2-java
cosmic
dne
bionic
dne
artful
dne
zesty
dne
xenial
dne
trusty
dne