PT-2017-19187 · Apache · Apache Struts

Published

2017-07-13

·

Updated

2019-10-03

·

CVE-2017-9787

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions prior to 2.5.12 Apache Struts versions prior to 2.3.33
Description The issue allows for a Denial of Service (DoS) attack when using Spring AOP functionality to secure Struts actions, even when a user is properly authenticated.
Recommendations For versions prior to 2.5.12, upgrade to Apache Struts version 2.5.12. For versions prior to 2.3.33, upgrade to Apache Struts version 2.3.33.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-9787
GHSA-8MR5-H28G-36QX

Affected Products

Apache Struts