PT-2006-1095 · Apache · Apache Struts

Published

2006-03-30

·

Updated

2025-10-22

·

CVE-2006-1547

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Apache Struts versions prior to 1.2.9
Description: The issue is related to errors in resource release in the getMultipartRequestHandler method of the Apache Struts platform. Exploitation of this issue can allow a remote attacker to cause a denial of service. This can be achieved by sending a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, providing further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
Recommendations: For versions prior to 1.2.9, update to version 1.2.9 or later to resolve the issue. As a temporary workaround, consider disabling the getMultipartRequestHandler method until a patch is available. Restrict access to the CommonsMultipartRequestHandler implementation to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04403
CVE-2006-1547
GHSA-7QWV-CWGJ-C8RJ

Affected Products

Apache Struts