PT-2016-3437 · Apache · Apache Struts

Alvaro Munoz

+1

·

Publicado

2016-06-01

·

Atualizado

2022-05-17

·

CVE-2016-4436

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions prior to 2.3.29 Apache Struts 2.5.x versions prior to 2.5.1
Description The issue is related to improper action name clean up, which may allow attackers to have an unspecified impact. It is also described as a vulnerability in the implementation of the action name cleanup method, associated with insufficient input validation. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.
Recommendations For Apache Struts versions prior to 2.3.29, update to version 2.3.29 or later. For Apache Struts 2.5.x versions prior to 2.5.1, update to version 2.5.1 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-06076
CVE-2016-4436
GHSA-XM92-V2MQ-842Q

Produtos afetados

Apache Struts