Skip to content
COOEY

EXPOSURES › CVE-2006-1547

CVE-2006-1547

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2006-1547 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Apache Struts 1 ActionForm DoS vulnerability exploited in the wild before patching.

Apache Struts 1 ActionForm contained a denial-of-service vulnerability in versions before 1.2.9 with BeanUtils 1.7, allowing attackers to disrupt services. DIB organizations must ensure legacy frameworks are patched or replaced, as unpatched CVEs remain actively exploited in the wild. This failure highlights the risk of relying on outdated software without a patching strategy.

Shame score — The vulnerability was actively exploited in the wild (KEV) and remained unpatched for years, demonstrating negligence in maintaining legacy systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.