Executive brief
ActionForm in Apache Struts allows remote attackers to cause a denial of service via multipart/form-data encoded forms. The vulnerability occurs when a parameter name references the public getMultipartRequestHandler method, granting unauthorized access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
Affected products
- Apache Software Foundation Struts before 1.2.9
- Apache Software Foundation BeanUtils 1.7
Timeline
- 2006-04-03: disclosed: Initial vulnerability report/bid date
- 2022-01-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-21: other: NVD publication date