In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Struts
Subscribe
|
|
Netapp
Subscribe
|
Oncommand Balance
Subscribe
|
|
Oracle
Subscribe
|
Agile Plm Framework
Subscribe
Enterprise Manager For Virtualization
Subscribe
Financial Services Hedge Management And Ifrs Valuations
Subscribe
Financial Services Market Risk Measurement And Management
Subscribe
Global Lifecycle Management Opatchauto
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Retail Order Broker
Subscribe
Retail Xstore Point Of Service
Subscribe
Webcenter Portal
Subscribe
Weblogic Server
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0714 | In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload. |
Github GHSA |
GHSA-xcrm-qpp8-hcw4 | Moderate severity vulnerability that affects org.apache.struts:struts2-rest-plugin |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T22:01:58.959Z
Reserved: 2017-10-21T00:00:00
Link: CVE-2017-15707
No data.
Status : Deferred
Published: 2017-12-01T16:29:00.247
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15707
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA