CVE-2015-2992
Java vulnerability analysis and mitigation

Overview

Apache Struts versions prior to 2.3.20 contain a cross-site scripting (XSS) vulnerability that affects directly accessible JSP files. The vulnerability was discovered and reported by Takayoshi Isayama of Mitsui Bussan Secure Directions, Inc. to IPA, and JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership (JVN Advisory, JVNDB).

Technical details

The vulnerability exists when JSP files can be accessed directly in Apache Struts, a software framework for creating web applications in Java. The CVSS v3.1 base score is 6.1 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network accessibility with low attack complexity but requiring user interaction (NVD).

Impact

When successfully exploited, this vulnerability allows an attacker to execute arbitrary scripts on the user's Internet Explorer browser when the XSS filter is turned off. This can lead to unauthorized access to and modification of data accessible through the vulnerable application (JVN Advisory).

Mitigation and workarounds

The following mitigations are recommended: 1) Update Apache Struts to version 2.3.20 or later, 2) Place JSP files under the 'WEB-INF' folder to avoid direct access, 3) Add a security constraint to the web.xml file (JVN Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-29847HIGH7.5
  • JavaJava
  • org.apache.linkis:linkis
NoYesJan 19, 2026
CVE-2026-1050MEDIUM6.9
  • JavaJava
  • net.risesoft:risenet-y9boot-support-platform-service
NoNoJan 17, 2026
CVE-2025-15104MEDIUM6.9
  • JavaScriptJavaScript
  • vnu-jar
NoNoJan 16, 2026
CVE-2025-59355MEDIUM6.5
  • JavaJava
  • org.apache.linkis:linkis-metadata
NoYesJan 19, 2026
CVE-2026-0858MEDIUM5.1
  • JavaJava
  • net.sourceforge.plantuml:plantuml
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management