← All CVEs

CVE-2015-0899

high · 7.5

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.

7.5
CVSS
21.3%
EPSS (exploit prob.)
97th
EPSS percentile
2016-07-04
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachestruts1.0
apachestruts1.0.2
apachestruts1.1
apachestruts1.1
apachestruts1.1
apachestruts1.1
apachestruts1.1
apachestruts1.1
apachestruts1.2.2
apachestruts1.2.4
apachestruts1.2.6
apachestruts1.2.7
apachestruts1.2.8
apachestruts1.2.9
apachestruts1.3.5
apachestruts1.3.8
apachestruts1.3.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-0899