PT-2016-2325 · Apache · Apache Struts

Published

2016-07-04

·

Updated

2022-05-13

·

CVE-2016-1181

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions 1.x through 1.3.10
Description The issue is related to errors in the code of the Apache Struts platform, specifically in the ActionServlet.java file, which mishandles multithreaded access to an ActionForm instance. This allows a remote attacker to execute arbitrary code or cause a denial of service via a multipart request. The vulnerability is exploited by sending a composite request, enabling the attacker to perform unauthorized actions.
Recommendations For Apache Struts versions 1.x through 1.3.10, consider disabling the ActionServlet.java file or restricting access to the ActionForm instance to minimize the risk of exploitation until a patch is available. Restrict access to the vulnerable module to prevent remote attackers from executing arbitrary code or causing a denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01714
CVE-2016-1181
GHSA-7JW3-5Q4W-89QG
MGASA-2016-0244

Affected Products

Apache Struts