VendorsApachestrutsany version
Vulnerabilities

Apache Struts any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2017-15707
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
Published 2017-12-01 · Modified
6.2EPSS 0.049
CVE-2016-4003
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.
Published 2016-04-12 · Modified
6.1EPSS 0.116
CVE-2015-5169
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
Published 2017-09-25 · Modified
6.1EPSS 0.075
CVE-2015-2992
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Published 2020-02-27 · Modified
6.1EPSS 0.058
CVE-2014-0094
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Published 2014-03-10 · Modified
5.02 PoCEPSS 0.996
CVE-2011-5057
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
Published 2012-01-08 · Modified
5.01 PoCEPSS 0.272
CVE-2006-1548
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
Published 2006-03-30 · Modified
4.3EPSS 0.055
← Prev2 / 2