CVE-2015-0899
Severity
7.5HIGH
EPSS
69.5%
top 1.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 4
Latest updateMay 14
Description
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
Patches
🔴Vulnerability Details
5📋Vendor Advisories
3🕵️Threat Intelligence
1Fortinet
▶
💬Community
5Bugzilla▶
CVE-2016-1181 struts: Vulnerability in ActionForm allows unintended remote operations against components on server memory↗2016-06-07
Bugzilla▶
CVE-2015-0899 struts: Apache Struts 1: input validation bypass in MultiPageValidator [fedora-all]↗2015-08-25
Bugzilla▶
CVE-2015-0899 struts: Apache Struts 1: input validation bypass in MultiPageValidator [epel-7]↗2015-08-25