ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Dec 12, 2025 | Dec 11, 2025 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Apr 27, 2018 | Jul 4, 2016 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 25388847 for version 12.2.1.0.0.Apply the Patch Set Update (PSU) 25388747 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 25388866 for version 12.2.1.2.0.Apply the Patch Set Update (PSU) 25388793 for version 12.1.3.0.0. | Apr 3, 2018 | Jul 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 7, 2016 |
| Struts | — | Migrate to Struts 2. | Jun 27, 2017 | Jul 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub