CVE-2006-1547
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache Struts 1 ActionForm Denial-of-Service Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 55% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-749
מוצרים מושפעים
apache: struts; apache: commons beanutils
קישורים
- http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html Broken LinkExploitPatchVendor Advisory
- http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html Broken LinkExploitPatchVendor Advisory
- http://issues.apache.org/bugzilla/show_bug.cgi?id=38534 Issue TrackingPermissions Required
- http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html Broken Link
- http://secunia.com/advisories/19493 Broken Link
- http://secunia.com/advisories/20117 Broken Link
- http://securitytracker.com/id?1015856 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/17342 Broken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2006/1205 Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25613 Third Party AdvisoryVDB Entry