First published: Mon Sep 14 2020(Updated: )
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Struts | >=2.0.0<=2.5.20 | |
Oracle Communications Policy Management | =12.5.0 | |
Oracle Financial Services Data Integration Hub | =8.0.3 | |
Oracle Financial Services Data Integration Hub | =8.0.6 | |
Oracle Financial Services Market Risk Measurement and Management | =8.0.6 | |
IBM Cognos Analytics | <=8.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0233 is a vulnerability that allows an attacker to cause a denial of service in Apache Struts 2.0.0 to 2.5.20 by overriding access permissions during file upload.
Apache Struts versions 2.0.0 to 2.5.20, Oracle Communications Policy Management version 12.5.0, Oracle Financial Services Data Integration Hub versions 8.0.3 and 8.0.6, and Oracle MySQL Enterprise Monitor up to version 8.0.23 are affected by CVE-2019-0233.
CVE-2019-0233 has a severity rating of 7.5, which is considered high.
To mitigate CVE-2019-0233, it is recommended to update to a patched version of the affected software or apply any necessary security patches provided by the vendor.
You can find more information about CVE-2019-0233 on the Apache Struts, Oracle, and SAP websites.