Security restrictions bypass in Apache Struts - CVE-2015-0899

 

Security restrictions bypass in Apache Struts - CVE-2015-0899

Published: December 26, 2017


Vulnerability identifier: #VU9754
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-0899
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to an error in the MultiPageValidator implementation in Apache Struts. A remote attacker can supply a modified page parameter to bypass intended access restrictions.

Affected software

Apache Struts
Debian Linux
Fedora
IBM Tivoli System Automation Application Manager
IBM Cloud Pak for Business Automation
Integration Designer
eDiscovery Manager
struts

How to mitigate CVE-2015-0899

Update to version 1.3.10.

struts - addressed in versions 1.3.10-14.fc22, 1.3.10-14.1.el7
eDiscovery Manager - update to 2.2.2.3.8
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001

External References

Related Security Bulletins