Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2017-15707

Disclosure Date: December 01, 2017
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • apache,
  • netapp,
  • oracle

Products

  • agile plm framework 9.3.6,
  • enterprise manager for virtualization 13.2.2,
  • enterprise manager for virtualization 13.2.3,
  • financial services hedge management and ifrs valuations 8.0.4,
  • financial services hedge management and ifrs valuations 8.0.5,
  • financial services market risk measurement and management 8.0.5,
  • global lifecycle management opatchauto,
  • jd edwards enterpriseone tools 9.2,
  • oncommand balance -,
  • retail order broker 5.2,
  • retail xstore point of service 15.0.1,
  • retail xstore point of service 16.0.2,
  • retail xstore point of service 6.5.11,
  • retail xstore point of service 7.0.6,
  • retail xstore point of service 7.1.6,
  • struts,
  • webcenter portal 12.2.1.2.0,
  • webcenter portal 12.2.1.3.0,
  • weblogic server 12.2.1.2,
  • weblogic server 12.2.1.3
Technical Analysis