PatchSiren

Apache CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Apache CVE published 2021-11-03

CVE-2017-9805

CVE-2017-9805 is identified in the supplied official records as an Apache Struts deserialization of untrusted data vulnerability. CISA includes it in the Known Exploited Vulnerabilities catalog, which means it should be treated as a real-world exploitation risk rather than a theoretical issue. The KEV entry directs defenders to apply updates per vendor instructions, and the supplied metadata marks known r [truncated]

Known exploited Apache CVE published 2021-11-03

CVE-2017-5638

CVE-2017-5638 is a remotely exploitable Apache Struts vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. CISA’s record marks it as requiring vendor-directed updates and notes known ransomware campaign use. For defenders, that combination makes this a high-priority patching and exposure review item for any environment running affected Struts deployments.

Known exploited Apache CVE published 2021-11-03

CVE-2016-4437

CVE-2016-4437 is recorded in the supplied corpus as an Apache Shiro code execution vulnerability and is listed by CISA in the Known Exploited Vulnerabilities catalog. CISA’s entry indicates confirmed exploitation and directs defenders to apply updates per vendor instructions. If Apache Shiro is present anywhere in your environment, treat this as a high-priority remediation item.

MEDIUM Apache CVE published 2017-02-02

CVE-2016-1566

CVE-2016-1566 is a stored cross-site scripting issue in the Guacamole file browser when file transfer is enabled to a location shared by multiple users. An authenticated remote user can inject arbitrary web script or HTML through a crafted filename, creating a browser-side attack surface for other users of the shared location. The vulnerability was fixed in guacamole.war on 2016-01-13, but the version num [truncated]

HIGH Apache CVE published 2017-01-18

CVE-2016-6497

CVE-2016-6497 is a high-severity LDAP integrity issue in Apache’s Groovy LDAP API. NVD describes it as an LDAP entry poisoning weakness caused by setting `returnObjFlag` to true for all search methods in `LDAP.java`. In practice, that means applications using the affected component may accept LDAP results in a way that can be manipulated by an attacker over the network, with the primary impact being data [truncated]

CRITICAL Apache CVE published 2017-01-13

CVE-2015-3188

CVE-2015-3188 is a critical remote code execution issue in the Apache Storm UI daemon. The official CVE/NVD record associates the problem with Apache Storm 0.10.0 beta-era deployments and gives it a CVSS 3.0 score of 9.8, indicating that exposed instances should be treated as urgent remediation items.