EXPOSURES › CVE-2006-1547
CVE-2006-1547
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Struts 1 ActionForm DoS vulnerability exploited in the wild before patching.
Apache Struts 1 ActionForm contained a denial-of-service vulnerability in versions before 1.2.9 with BeanUtils 1.7, allowing attackers to disrupt services. DIB organizations must ensure legacy frameworks are patched or replaced, as unpatched CVEs remain actively exploited in the wild. This failure highlights the risk of relying on outdated software without a patching strategy.
Shame score — The vulnerability was actively exploited in the wild (KEV) and remained unpatched for years, demonstrating negligence in maintaining legacy systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).