CVE-2015-0899
high · 7.5The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
7.5
CVSS
21.3%
EPSS (exploit prob.)
97th
EPSS percentile
2016-07-04
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | struts | 1.0 |
| apache | struts | 1.0.2 |
| apache | struts | 1.1 |
| apache | struts | 1.1 |
| apache | struts | 1.1 |
| apache | struts | 1.1 |
| apache | struts | 1.1 |
| apache | struts | 1.1 |
| apache | struts | 1.2.2 |
| apache | struts | 1.2.4 |
| apache | struts | 1.2.6 |
| apache | struts | 1.2.7 |
| apache | struts | 1.2.8 |
| apache | struts | 1.2.9 |
| apache | struts | 1.3.5 |
| apache | struts | 1.3.8 |
| apache | struts | 1.3.10 |
Check a specific version with /api/v1/cve/match.
References
- http://jvn.jp/en/jp/JVN86448949/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000042
- http://www.debian.org/security/2016/dsa-3536
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/74423
- https://en.osdn.jp/projects/terasoluna/wiki/StrutsPatch2-EN
- https://security.netapp.com/advisory/ntap-20180629-0006/
- http://jvn.jp/en/jp/JVN86448949/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000042
- http://www.debian.org/security/2016/dsa-3536
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/74423
- https://en.osdn.jp/projects/terasoluna/wiki/StrutsPatch2-EN
- https://security.netapp.com/advisory/ntap-20180629-0006/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-0899