CVE-2015-0899: Input Validation
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0899?
CVE-2015-0899 has been classified as a high severity vulnerability due to its potential for remote exploitation and the ability to bypass access restrictions.
How do I fix CVE-2015-0899?
To fix CVE-2015-0899, update Apache Struts to a version later than 1.3.10 where the vulnerability is patched.
What versions of Apache Struts are affected by CVE-2015-0899?
CVE-2015-0899 affects Apache Struts versions 1.1 through 1.3.10.
Can CVE-2015-0899 lead to unauthorized access?
Yes, exploiting CVE-2015-0899 can allow remote attackers to gain unauthorized access to restricted areas of a web application.
What is the nature of the vulnerability in CVE-2015-0899?
The vulnerability in CVE-2015-0899 allows bypassing of intended access restrictions through a modified page parameter in the MultiPageValidator implementation.