CVE-2017-15707

Impact:
Moderate
Public Date:
2017-12-01
CWE:
CWE-20
Bugzilla:
1522794: CVE-2017-15707 struts2: Crafted JSON request can result in DoS

The MITRE CVE dictionary describes this issue as:

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Find out more about CVE-2017-15707 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect any of the Red Hat products as they did not include the Apache Struts 2 package.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat JBoss Fuse Service Works 6 struts2-core Not affected

External References

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.