6.2
CVE-2017-15707
- EPSS 4.89%
- Veröffentlicht 01.12.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Oncommand Balance Version -
Oracle ≫ Agile Plm Framework Version 9.3.6
Oracle ≫ Enterprise Manager For Virtualization Version 13.2.2
Oracle ≫ Enterprise Manager For Virtualization Version 13.2.3
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version 8.0.4
Oracle ≫ Financial Services Hedge Management And Ifrs Valuations Version 8.0.5
Oracle ≫ Financial Services Market Risk Measurement And Management Version 8.0.5
Oracle ≫ Jd Edwards Enterpriseone Tools Version 9.2
Oracle ≫ Retail Order Broker Version 5.2
Oracle ≫ Retail Xstore Point Of Service Version 6.5.11
Oracle ≫ Retail Xstore Point Of Service Version 7.0.6
Oracle ≫ Retail Xstore Point Of Service Version 7.1.6
Oracle ≫ Retail Xstore Point Of Service Version 15.0.1
Oracle ≫ Retail Xstore Point Of Service Version 16.0.2
Oracle ≫ Webcenter Portal Version 12.2.1.2.0
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.2
Oracle ≫ Weblogic Server Version 12.2.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.89% | 0.909 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.2 | 2.5 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
http://www.securityfocus.com/bid/102021
http://www.securitytracker.com/id/1039946
https://cwiki.apache.org/confluence/display/WW/S2-054
https://security.netapp.com/advisory/ntap-20171214-0001/