Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9793

Опубликовано: 20 сент. 2017
Источник: debian
EPSS Средний

Описание

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libstruts1.2-javaremovedpackage
libstruts1.2-javanot-affectedwheezypackage

Примечания

  • https://struts.apache.org/docs/s2-051.html

EPSS

Процентиль: 94%
0.13427
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.

CVSS3: 5.9
redhat
больше 8 лет назад

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.

CVSS3: 7.5
nvd
больше 8 лет назад

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.

CVSS3: 7.5
github
больше 7 лет назад

The REST Plugin in Apache Struts is using an outdated XStream library

CVSS3: 7.5
fstec
больше 8 лет назад

Уязвимость библиотеки struts2-core программной платформы Apache Struts, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.13427
Средний
Уязвимость CVE-2017-9793