ZeroHour

CVE-2017-15707

CVSS 3.0
6.2 medium
EPSS
5%p92
Published
()
Modified
Description

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Vendors
apachenetapporacle
Products
struts, oncommand balance, agile plm framework, enterprise manager for virtualization, financial services hedge management and ifrs valuations, financial services market risk measurement and management, global lifecycle management opatchauto, jd edwards enterpriseone tools, retail order broker, retail xstore point of service, webcenter portal, weblogic server
Weakness
CWE-20
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.