CVE-2015-5209

NameCVE-2015-5209
DescriptionApache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libstruts1.2-javasourcewheezy(not affected)
libstruts1.2-javasource(unstable)(unfixed)

Notes

[wheezy] - libstruts1.2-java <not-affected> (Only affects versions >= 2.x)
https://struts.apache.org/docs/s2-026.html

Search for package or bug name: Reporting problems