Junglewise Threat Intelligence

CVE-2006-1547: Apache Struts 1 ActionForm Denial-of-Service Vulnerability

CVE-2006-1547 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-01-21

Vendors: Apache, Apache Software Foundation.

Executive brief

ActionForm in Apache Struts allows remote attackers to cause a denial of service via multipart/form-data encoded forms. The vulnerability occurs when a parameter name references the public getMultipartRequestHandler method, granting unauthorized access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

Affected products

  • Apache Software Foundation Struts before 1.2.9
  • Apache Software Foundation BeanUtils 1.7

Timeline

  • 2006-04-03: disclosed: Initial vulnerability report/bid date
  • 2022-01-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-21: other: NVD publication date

Related threats