PT-2016-3437 · Apache · Apache Struts

Alvaro Munoz

+1

·

Published

2016-06-01

·

Updated

2022-05-17

·

CVE-2016-4436

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions prior to 2.3.29 Apache Struts 2.5.x versions prior to 2.5.1
Description The issue is related to improper action name clean up, which may allow attackers to have an unspecified impact. It is also described as a vulnerability in the implementation of the action name cleanup method, associated with insufficient input validation. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.
Recommendations For Apache Struts versions prior to 2.3.29, update to version 2.3.29 or later. For Apache Struts 2.5.x versions prior to 2.5.1, update to version 2.5.1 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06076
CVE-2016-4436
GHSA-XM92-V2MQ-842Q

Affected Products

Apache Struts