PT-2016-7114 · Apache · Apache Struts
Published
2016-10-05
·
Updated
2022-05-14
·
CVE-2016-6795
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Struts versions 2.3.x through 2.3.30
Apache Struts versions 2.5.x through 2.5.4
Description
A path traversal issue in Apache Struts allows attackers to execute arbitrary code on the server side using a specially crafted URL. This issue is related to the Convention plugin and is only exploitable when this plugin is used in conjunction with Apache Struts.
Recommendations
For Apache Struts versions 2.3.x through 2.3.30, update to version 2.3.31 or later.
For Apache Struts versions 2.5.x through 2.5.4, update to version 2.5.5 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Struts