Описание
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
Ссылки
- Vendor Advisory
- Third Party AdvisoryVDB EntryVendor Advisory
- Patch
- PatchThird Party Advisory
- Patch
- Patch
- PatchThird Party Advisory
- Patch
- Patch
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue Tracking
- Issue TrackingPatch
- Third Party Advisory
- Third Party Advisory
- Patch
Уязвимые конфигурации
Одно из
Одно из
EPSS
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles mu ...
Уязвимость программной платформы Apache Struts, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
EPSS
8.1 High
CVSS3
6.8 Medium
CVSS2