CVE-2015-0899

Description

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
75.256

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.14Windows
Multiple vulnerabilities are fixed in IBM WebSphere 9.0.0.8Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Vulnerabilities CVE-2015-0899,CVE-2023-49735 are affected in Apache - Struts 1.2.9Windows
Vulnerabilities CVE-2015-0899 are affected in Apache - struts-core 1.3.10Windows
Vulnerabilities CVE-2015-0899,CVE-2023-49735 are affected in Apache - Struts for Linux 1.2.9Linux
Vulnerabilities CVE-2015-0899 are affected in Apache - struts-core for Linux 1.3.10Linux
Improper Input Validation Vulnerability (CVE-2015-0899)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234