// For flags

CVE-2017-15707

 

Severity Score

6.2
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

El plugin REST en Apache Struts desde la versión 2.5 hasta la 2.5.14 emplea una librería JSON-lib desactualizada vulnerable y que permite llevar a cabo un ataque de denegación de servicio utilizando una petición maliciosa con una carga útil JSON especialmente manipulada.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-10-21 CVE Reserved
  • 2017-12-01 CVE Published
  • 2023-06-03 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Struts
Search vendor "Apache" for product "Struts"
>= 2.5 <= 2.5.14
Search vendor "Apache" for product "Struts" and version " >= 2.5 <= 2.5.14"
-
Affected
Netapp
Search vendor "Netapp"
Oncommand Balance
Search vendor "Netapp" for product "Oncommand Balance"
--
Affected
Oracle
Search vendor "Oracle"
Agile Plm Framework
Search vendor "Oracle" for product "Agile Plm Framework"
9.3.6
Search vendor "Oracle" for product "Agile Plm Framework" and version "9.3.6"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager For Virtualization
Search vendor "Oracle" for product "Enterprise Manager For Virtualization"
13.2.2
Search vendor "Oracle" for product "Enterprise Manager For Virtualization" and version "13.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager For Virtualization
Search vendor "Oracle" for product "Enterprise Manager For Virtualization"
13.2.3
Search vendor "Oracle" for product "Enterprise Manager For Virtualization" and version "13.2.3"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Hedge Management And Ifrs Valuations
Search vendor "Oracle" for product "Financial Services Hedge Management And Ifrs Valuations"
8.0.4
Search vendor "Oracle" for product "Financial Services Hedge Management And Ifrs Valuations" and version "8.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Hedge Management And Ifrs Valuations
Search vendor "Oracle" for product "Financial Services Hedge Management And Ifrs Valuations"
8.0.5
Search vendor "Oracle" for product "Financial Services Hedge Management And Ifrs Valuations" and version "8.0.5"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Market Risk Measurement And Management
Search vendor "Oracle" for product "Financial Services Market Risk Measurement And Management"
8.0.5
Search vendor "Oracle" for product "Financial Services Market Risk Measurement And Management" and version "8.0.5"
-
Affected
Oracle
Search vendor "Oracle"
Global Lifecycle Management Opatchauto
Search vendor "Oracle" for product "Global Lifecycle Management Opatchauto"
*-
Affected
Oracle
Search vendor "Oracle"
Jd Edwards Enterpriseone Tools
Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools"
9.2
Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" and version "9.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
5.2
Search vendor "Oracle" for product "Retail Order Broker" and version "5.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
6.5.11
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "6.5.11"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
7.0.6
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
7.1.6
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.1.6"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
15.0.1
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "15.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
16.0.2
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "16.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.2.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.3.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
12.2.1.2
Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
12.2.1.3
Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3"
-
Affected