ZeroHour

CVE-2006-1547

KEVmass

Denial-of-Service in Apache Struts 1 ActionForm (pre-1.2.9)

CISA: Apache Struts 1 ActionForm Denial-of-Service Vulnerability

CVSS
EPSS
55%p99
Published
KEV added
AI analysis

Apache Struts 1 versions before 1.2.9, when used with BeanUtils 1.7, contain a denial-of-service vulnerability in how ActionForm beans are populated from request data. An attacker can send crafted HTTP request parameters that, when applied to an ActionForm via BeanUtils, consume excessive server resources and disrupt or crash the affected web application. The impact is availability only — no code execution or access — so an unauthenticated remote attacker gains the ability to degrade or take down the service. Any organization running legacy Java web applications built on Apache Struts 1 prior to 1.2.9 is affected. CISA added this flaw to its Known Exploited Vulnerabilities Catalog on 2022-01-21, confirming in-the-wild exploitation; no public proof-of-concept is known, and any ransomware association is not reported.

What to do: Upgrade Apache Struts 1 to version 1.2.9 or later as required by CISA's KEV catalog, and inventory deployed WAR/EAR files for bundled Struts 1 and BeanUtils 1.7 jars since the framework is end-of-life. For legacy applications that cannot be patched or migrated to a supported framework, restrict internet exposure or apply WAF/request-filtering controls to limit unauthenticated access to the vulnerable form-handling paths.

Affected
Apache Struts 1versions before 1.2.9 (when used with BeanUtils 1.7)
Estimated exposure
mass≈100,000+ exposed systems/applications — Struts 1 was one of the most widely deployed Java web frameworks of the 2000s and persists in legacy enterprise web applications, with public internet scans commonly surfacing tens of thousands of exposed Struts hosts, supporting an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Apache Struts 1
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Apache
Products
Struts 1

In the news

AI AppSec tools agree on just 5% of security findings

Contrast Security report finds 42 confirmed exploit attempts per application monthly and three AI scanners agreeing on only 5% of findings.

Contrast Security's AppSec Overflow 2026 report, drawing on telemetry from hundreds of thousands of production applications and APIs, found adversaries touch the average application every four minutes with 42 confirmed viable exploit attempts per application monthly, led by untrusted deserialization, path traversal, and method tampering. Legacy flaws Log4Shell and Spring4Shell remain widespread, mean time to exploit fell from over two years in 2018 to under three weeks for most 2025 exploited vulnerabilities, and average critical fix time is 92 days. Three AI scanners set on the same codebase agreed on only 5% of findings, and triaging a 2-million-line codebase scan cost roughly $128,000 versus $315 in API charges. Among exploited CVEs in the dataset, 82% of KEV-listed entries carried EPSS scores of 90% or higher, while CVE-2006-1547 and CVE-2023-38180 were confirmed exploited despite EPSS scores under 25%.

Help Net Security · 15d agoResearch in the wildCVE-2006-1547CVE-2023-381801