Lucene search

K
f5F5F5:K35226442
HistorySep 11, 2020 - 12:00 a.m.

K35226442 : Apache Struts vulnerabilities CVE-2019-0233 and CVE-2019-0230

2020-09-1100:00:00
my.f5.com
17

7.5 High

AI Score

Confidence

Low

0.953 High

EPSS

Percentile

99.4%

Security Advisory Description

An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Impact

An attacker may be able to use these vulnerabilities to cause a denial of service (DoS) during file uploads, and remotely run code.