CVE-2015-5209: Input Validation
Published Aug 29, 2017
·Updated
Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
Affected Software
66 affected components
Apache struts=2.0.0
Apache struts=2.0.1
Apache struts=2.0.2
Apache struts=2.0.3
Apache struts=2.0.4
Apache struts=2.0.5
Apache struts=2.0.6
Apache struts=2.0.7
Apache struts=2.0.8
Apache struts=2.0.9
Apache struts=2.0.10
Apache struts=2.0.11
Apache struts=2.0.11.1
Apache struts=2.0.11.2
Apache struts=2.0.12
Apache struts=2.0.13
Apache struts=2.0.14
Apache struts=2.1.0
Apache struts=2.1.1
Apache struts=2.1.2
Apache struts=2.1.3
Apache struts=2.1.4
Apache struts=2.1.5
Apache struts=2.1.6
Apache struts=2.1.8
Apache struts=2.1.8.1
Apache struts=2.2.1
Apache struts=2.2.1.1
Apache struts=2.2.3
Apache struts=2.2.3.1
Apache struts=2.3.1
Apache struts=2.3.1.1
Apache struts=2.3.1.2
Apache struts=2.3.3
Apache struts=2.3.4
Apache struts=2.3.4.1
Apache struts=2.3.5
Apache struts=2.3.6
Apache struts=2.3.7
Apache struts=2.3.8
Apache struts=2.3.9
Apache struts=2.3.10
Apache struts=2.3.11
Apache struts=2.3.12
Apache struts=2.3.13
Apache struts=2.3.14
Apache struts=2.3.14.1
Apache struts=2.3.14.2
Apache struts=2.3.14.3
Apache struts=2.3.15
Apache struts=2.3.15.1
Apache struts=2.3.15.2
Apache struts=2.3.15.3
Apache struts=2.3.16
Apache struts=2.3.16.1
Apache struts=2.3.16.2
Apache struts=2.3.16.3
Apache struts=2.3.17
Apache struts=2.3.19
Apache struts=2.3.20
Apache struts=2.3.20.1
Apache struts=2.3.20.2
Apache struts=2.3.21
Apache struts=2.3.22
Apache struts=2.3.23
Apache struts=2.3.24
Event History
Aug 29, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5209?
CVE-2015-5209 has a severity rating of critical due to its ability to allow remote attackers to manipulate application internals.
2
How do I fix CVE-2015-5209?
To fix CVE-2015-5209, you should upgrade to Apache Struts version 2.3.24.1 or later.
3
What types of attacks can CVE-2015-5209 enable?
CVE-2015-5209 can enable remote attackers to alter user sessions and manipulate underlying container settings.
4
Which versions of Apache Struts are affected by CVE-2015-5209?
CVE-2015-5209 affects all Apache Struts 2.x versions prior to 2.3.24.1.
5
Is CVE-2015-5209 generally exploitable?
Yes, CVE-2015-5209 is generally considered exploitable by attackers targeting vulnerable versions of Apache Struts.