CVE-2015-0899 describes an access restriction bypass vulnerability in Apache Struts 1 versions 1.1 through 1.3.10, specifically within its MultiPageValidator implementation. This flaw allows remote attackers to bypass intended security controls by manipulating the 'page' parameter. With a CVSS score of 7.5 (HIGH), it presents a low complexity attack vector over the network, potentially leading to high integrity impact without requiring user interaction. While no public exploit code or active exploitation is indicated, its high FAUCET Risk Score and notable community discussion suggest it warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:apache:struts:1.0:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:apache:struts:1.0.2:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:1.1:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:1.1:b1:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:1.1:b2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.