cbcvebase.
CVE-2017-15707
published 2017-12-01

CVE-2017-15707: In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious…

medium6.2CVSS 3.0
AVLACLPRNUINSUCNINAH
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Affected

19 ranges
VendorProductVersion rangeFixed in
apachestruts2.5 – 2.5.14
apache_software_foundationapache_struts
oracleagile_plm_framework
oracleenterprise_manager_for_virtualization
oracleenterprise_manager_for_virtualization
oraclefinancial_services_hedge_management_and_ifrs_valuations
oraclefinancial_services_hedge_management_and_ifrs_valuations
oraclefinancial_services_market_risk_measurement_and_management
oraclejd_edwards_enterpriseone_tools
oracleretail_order_broker
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
oraclewebcenter_portal
oraclewebcenter_portal
oracleweblogic_server
oracleweblogic_server