CVE-2017-15707

Published on: 12/01/2017 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:26:33 PM UTC

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain versions of Struts from Apache contain the following vulnerability:

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

  • CVE-2017-15707 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as MEDIUM severity.
  • Affected Vendor/Software: URL Logo Apache Software Foundation - Apache Struts version 2.5 to 2.5.14

CVSS3 Score: 6.2 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE NONE HIGH

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE NONE PARTIAL

CVE References

Description Tags Link
Apache Struts REST Plugin JSON Library Bug Lets Remote Users Deny Service - SecurityTracker Third Party Advisory
VDB Entry
www.securitytracker.com
text/html
URL Logo SECTRACK 1039946
Apache Struts CVE-2017-15707 Denial of Service Vulnerability Third Party Advisory
VDB Entry
cve.report (archive)
text/html
URL Logo BID 102021
CPU July 2018 Patch
www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
Oracle Critical Patch Update - April 2018 Patch
www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
S2-054 - Apache Struts 2 Documentation - Apache Software Foundation Patch
Vendor Advisory
cwiki.apache.org
text/html
URL Logo CONFIRM cwiki.apache.org/confluence/display/WW/S2-054
CVE-2017-15707 Apache Struts Vulnerability in NetApp Products | NetApp Product Security Third Party Advisory
security.netapp.com
text/html
URL Logo CONFIRM security.netapp.com/advisory/ntap-20171214-0001/

Related QID Numbers

  • 980793 Java (maven) Security Update for org.apache.struts:struts2-rest-plugin (GHSA-xcrm-qpp8-hcw4)

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationApacheStrutsAllAllAllAll
ApplicationNetappOncommand Balance-AllAllAll
ApplicationNetappOncommand Balance-AllAllAll
ApplicationOracleAgile Plm Framework9.3.6AllAllAll
ApplicationOracleAgile Plm Framework9.3.6AllAllAll
ApplicationOracleEnterprise Manager For Virtualization13.2.2AllAllAll
ApplicationOracleEnterprise Manager For Virtualization13.2.3AllAllAll
ApplicationOracleEnterprise Manager For Virtualization13.2.2AllAllAll
ApplicationOracleEnterprise Manager For Virtualization13.2.3AllAllAll
ApplicationOracleFinancial Services Hedge Management And Ifrs Valuations8.0.4AllAllAll
ApplicationOracleFinancial Services Hedge Management And Ifrs Valuations8.0.5AllAllAll
ApplicationOracleFinancial Services Hedge Management And Ifrs Valuations8.0.4AllAllAll
ApplicationOracleFinancial Services Hedge Management And Ifrs Valuations8.0.5AllAllAll
ApplicationOracleFinancial Services Market Risk Measurement And Management8.0.5AllAllAll
ApplicationOracleFinancial Services Market Risk Measurement And Management8.0.5AllAllAll
ApplicationOracleGlobal Lifecycle Management OpatchautoAllAllAllAll
ApplicationOracleGlobal Lifecycle Management OpatchautoAllAllAllAll
ApplicationOracleJd Edwards Enterpriseone Tools9.2AllAllAll
ApplicationOracleJd Edwards Enterpriseone Tools9.2AllAllAll
ApplicationOracleRetail Order Broker5.2AllAllAll
ApplicationOracleRetail Order Broker5.2AllAllAll
ApplicationOracleRetail Xstore Point Of Service15.0.1AllAllAll
ApplicationOracleRetail Xstore Point Of Service16.0.2AllAllAll
ApplicationOracleRetail Xstore Point Of Service6.5.11AllAllAll
ApplicationOracleRetail Xstore Point Of Service7.0.6AllAllAll
ApplicationOracleRetail Xstore Point Of Service7.1.6AllAllAll
ApplicationOracleRetail Xstore Point Of Service15.0.1AllAllAll
ApplicationOracleRetail Xstore Point Of Service16.0.2AllAllAll
ApplicationOracleRetail Xstore Point Of Service6.5.11AllAllAll
ApplicationOracleRetail Xstore Point Of Service7.0.6AllAllAll
ApplicationOracleRetail Xstore Point Of Service7.1.6AllAllAll
ApplicationOracleWebcenter Portal12.2.1.2.0AllAllAll
ApplicationOracleWebcenter Portal12.2.1.3.0AllAllAll
ApplicationOracleWebcenter Portal12.2.1.2.0AllAllAll
ApplicationOracleWebcenter Portal12.2.1.3.0AllAllAll
ApplicationOracleWeblogic Server12.2.1.2AllAllAll
ApplicationOracleWeblogic Server12.2.1.3AllAllAll
ApplicationOracleWeblogic Server12.2.1.2AllAllAll
ApplicationOracleWeblogic Server12.2.1.3AllAllAll
  • cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*:
  • cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:agile_plm_framework:9.3.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:agile_plm_framework:9.3.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_for_virtualization:13.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:global_lifecycle_management_opatchauto:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:global_lifecycle_management_opatchauto:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_order_broker:5.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_order_broker:5.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:6.5.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:7.0.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:6.5.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:7.0.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:webcenter_portal:12.2.1.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:webcenter_portal:12.2.1.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:weblogic_server:12.2.1.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:weblogic_server:12.2.1.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:weblogic_server:12.2.1.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:weblogic_server:12.2.1.3:*:*:*:*:*:*:*:
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report