The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libstruts1.2-java | Apr 7, 2016 | Mar 31, 2016 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Jun 28, 2018 | Jul 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 30, 2015 |
| Struts | — | Migrate to Struts 2. | Jun 27, 2017 | Jul 4, 2016 |
| Suse | — | Upgrade strutsUpgrade struts-javadocUpgrade struts-manual | Dec 18, 2015 | May 15, 2015 |
| Ubuntu | — | Upgrade libstruts1.2-java | Nov 19, 2024 | Jul 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub