PT-2017-9773 · Apache · Apache Struts

Published

2017-09-20

·

Updated

2022-05-14

·

CVE-2016-8738

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.5 through 2.5.5
Description The issue allows an attacker to prepare a special URL that can overload the server process when the built-in URLValidator is used to validate the URL. This can happen if an application allows entering a URL in a form field.
Recommendations For Apache Struts versions 2.5 through 2.5.5, consider disabling the built-in URLValidator until a patch is available to prevent potential server overload. Restrict access to form fields that allow URL entry to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8738
GHSA-86VQ-8QHC-5RQW

Affected Products

Apache Struts