PT-2017-19187 · Apache · Apache Struts
Published
2017-07-13
·
Updated
2019-10-03
·
CVE-2017-9787
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Struts versions prior to 2.5.12
Apache Struts versions prior to 2.3.33
Description
The issue allows for a Denial of Service (DoS) attack when using Spring AOP functionality to secure Struts actions, even when a user is properly authenticated.
Recommendations
For versions prior to 2.5.12, upgrade to Apache Struts version 2.5.12.
For versions prior to 2.3.33, upgrade to Apache Struts version 2.3.33.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Struts