MEDIUM · 6.2

CVE-2017-15707

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Vulnerability Description

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

CVSS Score

6.2

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheStruts>= 2.5, <= 2.5.14
NetappOncommand Balance-
OracleAgile Plm Framework9.3.6
OracleEnterprise Manager For Virtualization13.2.2
OracleFinancial Services Hedge Management And Ifrs Valuations8.0.4
OracleFinancial Services Market Risk Measurement And Management8.0.5
OracleGlobal Lifecycle Management OpatchautoAll versions
OracleJd Edwards Enterpriseone Tools9.2
OracleRetail Order Broker5.2
OracleRetail Xstore Point Of Service6.5.11
OracleWebcenter Portal12.2.1.2.0
OracleWeblogic Server12.2.1.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-15707?

CVE-2017-15707 is a vulnerability with a CVSS score of 6.2 (MEDIUM). In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

How severe is CVE-2017-15707?

CVE-2017-15707 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-15707?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Struts, Netapp Oncommand Balance, Oracle Agile Plm Framework, Oracle Enterprise Manager For Virtualization, Oracle Financial Services Hedge Management And Ifrs Valuations.