CVE-2006-1547
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 54.63% probability · 99th percentile
- CISA KEV
- Listed 21 January 2022 · due 21 July 2022
- Weakness
- CWE-749
- Affected
- apache/struts
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2006-1547
References
- http://issues.apache.org/bugzilla/show_bug.cgi?id=38534Issue Tracking, Permissions Required
- http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlBroken Link
- http://secunia.com/advisories/19493Broken Link
- http://secunia.com/advisories/20117Broken Link
- http://securitytracker.com/id?1015856Broken Link, Third Party Advisory, VDB Entry
- http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.htmlBroken Link, Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/17342Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/1205Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25613Third Party Advisory, VDB Entry
- http://issues.apache.org/bugzilla/show_bug.cgi?id=38534Issue Tracking, Permissions Required
- http://lists.suse.com/archive/suse-security-announce/2006-May/0004.htmlBroken Link
- http://secunia.com/advisories/19493Broken Link
- http://secunia.com/advisories/20117Broken Link
- http://securitytracker.com/id?1015856Broken Link, Third Party Advisory, VDB Entry
- http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.htmlBroken Link, Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/17342Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/1205Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25613Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-1547US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.