CVE-2017-15707: Apache Struts

Medium severity, CVSS 6.2. EPSS: 4.9% chance of exploitation in the next 30 days.

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

Affected products

  • Apache Struts: from 2.5, up to and including 2.5.14
  • Netapp Oncommand Balance: affected versions not specified
  • Oracle Agile PLM Framework: version 9.3.6 only
  • Oracle Enterprise Manager For Virtualization: version 13.2.2 only; version 13.2.3 only
  • Oracle Financial Services Hedge Management And Ifrs Valuations: version 8.0.4 only; version 8.0.5 only
  • Oracle Financial Services Market Risk Measurement And Management: version 8.0.5 only
  • Oracle Global Lifecycle Management Opatchauto: any version
  • Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
  • Oracle Retail Order Broker: version 5.2 only
  • Oracle Retail Xstore Point Of Service: version 6.5.11 only; version 7.0.6 only; version 7.1.6 only; version 15.0.1 only; version 16.0.2 only
  • Oracle Webcenter Portal: version 12.2.1.2.0 only; version 12.2.1.3.0 only
  • Oracle WebLogic Server: version 12.2.1.2 only; version 12.2.1.3 only

Published 2017-12-01. Last modified 2026-06-17.