Vulnerabilities > Apache > Struts > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-15 CVE-2017-9805 Deserialization of Untrusted Data vulnerability in multiple products
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
network
high complexity
apache cisco netapp CWE-502
8.1
2017-08-29 CVE-2015-5209 Improper Input Validation vulnerability in Apache Struts
Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
network
low complexity
apache CWE-20
7.5
2017-07-13 CVE-2017-9787 Unspecified vulnerability in Apache Struts
When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack.
network
low complexity
apache
7.5
2016-07-04 CVE-2016-4433 Improper Input Validation vulnerability in Apache Struts
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
network
low complexity
apache CWE-20
7.5
2016-07-04 CVE-2016-4431 Improper Input Validation vulnerability in Apache Struts
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.
network
low complexity
apache CWE-20
7.5
2016-07-04 CVE-2016-4430 Cross-Site Request Forgery (CSRF) vulnerability in Apache Struts
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
network
low complexity
apache CWE-352
8.8
2016-07-04 CVE-2016-1182 Improper Input Validation vulnerability in Apache Struts
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.
network
low complexity
apache CWE-20
8.2
2016-07-04 CVE-2016-1181 ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
network
high complexity
oracle apache
8.1
2016-07-04 CVE-2015-0899 Improper Input Validation vulnerability in Apache Struts
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
network
low complexity
apache CWE-20
7.5
2016-04-26 CVE-2016-3081 Command Injection vulnerability in multiple products
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
network
high complexity
apache oracle CWE-77
8.1