Vulnerability Description
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Struts | >= 2.5, <= 2.5.14 |
| Netapp | Oncommand Balance | - |
| Oracle | Agile Plm Framework | 9.3.6 |
| Oracle | Enterprise Manager For Virtualization | 13.2.2 |
| Oracle | Financial Services Hedge Management And Ifrs Valuations | 8.0.4 |
| Oracle | Financial Services Market Risk Measurement And Management | 8.0.5 |
| Oracle | Global Lifecycle Management Opatchauto | All versions |
| Oracle | Jd Edwards Enterpriseone Tools | 9.2 |
| Oracle | Retail Order Broker | 5.2 |
| Oracle | Retail Xstore Point Of Service | 6.5.11 |
| Oracle | Webcenter Portal | 12.2.1.2.0 |
| Oracle | Weblogic Server | 12.2.1.2 |
Related Weaknesses (CWE)
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch
- http://www.securityfocus.com/bid/102021Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039946Third Party AdvisoryVDB Entry
- https://cwiki.apache.org/confluence/display/WW/S2-054PatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20171214-0001/Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch
- http://www.securityfocus.com/bid/102021Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039946Third Party AdvisoryVDB Entry
- https://cwiki.apache.org/confluence/display/WW/S2-054PatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20171214-0001/Third Party Advisory
FAQ
What is CVE-2017-15707?
CVE-2017-15707 is a vulnerability with a CVSS score of 6.2 (MEDIUM). In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
How severe is CVE-2017-15707?
CVE-2017-15707 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15707?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Struts, Netapp Oncommand Balance, Oracle Agile Plm Framework, Oracle Enterprise Manager For Virtualization, Oracle Financial Services Hedge Management And Ifrs Valuations.