imPC@ndo IT

Tracker / CVE-2017-15707

CVE-2017-15707

Medium 6.2

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Affected products and versions

apache struts · 2.5 → 2.5.14
netapp oncommand_balance
oracle agile_plm_framework
oracle enterprise_manager_for_virtualization
oracle financial_services_hedge_management_and_ifrs_valuations
oracle financial_services_market_risk_measurement_and_management
oracle global_lifecycle_management_opatchauto
oracle jd_edwards_enterpriseone_tools
oracle retail_order_broker
oracle retail_xstore_point_of_service
oracle webcenter_portal
oracle weblogic_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References