opensymphony records
4 published records for vendor opensymphony.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2007-4556Proof of concept | Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all inpopensymphony · xwork | Medium6.8 | — | 25.7% | Aug 27, 2007 |
31Monitor | CVE-2008-6504Proof of concept | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does notopensymphony · xwork · CWE-20 | Medium5.0 | — | 36.6% | Mar 23, 2009 |
22Monitor | CVE-2011-2088No exploit | XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive apache · struts · CWE-200 | Medium5.0 | — | 6.1% | May 13, 2011 |
20Monitor | CVE-2011-1772Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWoapache · struts · CWE-79 | Low2.6 | — | 33.3% | May 13, 2011 |
- CVE-2007-455635Monitor
Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all inp
MediumCVSS 6.8Proof of conceptEPSS 26%opensymphony · xworkAug 27, 2007
- CVE-2008-650431Monitor
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not
MediumCVSS 5.0Proof of conceptEPSS 37%opensymphony · xworkMar 23, 2009
- CVE-2011-208822Monitor
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive
MediumCVSS 5.0No exploitEPSS 6%apache · strutsMay 13, 2011
- CVE-2011-177220Monitor
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWo
LowCVSS 2.6Proof of conceptEPSS 33%apache · strutsMay 13, 2011