CVE Vulnerabilities

CVE-2016-4436

Published: Oct 03, 2016 | Modified: Aug 09, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.9 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

Affected Software

Name Vendor Start Version End Version
Struts Apache 2.0.0 (including) 2.0.0 (including)
Struts Apache 2.0.1 (including) 2.0.1 (including)
Struts Apache 2.0.2 (including) 2.0.2 (including)
Struts Apache 2.0.3 (including) 2.0.3 (including)
Struts Apache 2.0.4 (including) 2.0.4 (including)
Struts Apache 2.0.5 (including) 2.0.5 (including)
Struts Apache 2.0.6 (including) 2.0.6 (including)
Struts Apache 2.0.7 (including) 2.0.7 (including)
Struts Apache 2.0.8 (including) 2.0.8 (including)
Struts Apache 2.0.9 (including) 2.0.9 (including)
Struts Apache 2.0.11 (including) 2.0.11 (including)
Struts Apache 2.0.11.1 (including) 2.0.11.1 (including)
Struts Apache 2.0.11.2 (including) 2.0.11.2 (including)
Struts Apache 2.0.12 (including) 2.0.12 (including)
Struts Apache 2.0.14 (including) 2.0.14 (including)
Struts Apache 2.1.6 (including) 2.1.6 (including)
Struts Apache 2.1.8 (including) 2.1.8 (including)
Struts Apache 2.1.8.1 (including) 2.1.8.1 (including)
Struts Apache 2.2.1 (including) 2.2.1 (including)
Struts Apache 2.2.1.1 (including) 2.2.1.1 (including)
Struts Apache 2.2.3 (including) 2.2.3 (including)
Struts Apache 2.2.3.1 (including) 2.2.3.1 (including)
Struts Apache 2.3.1 (including) 2.3.1 (including)
Struts Apache 2.3.1.1 (including) 2.3.1.1 (including)
Struts Apache 2.3.1.2 (including) 2.3.1.2 (including)
Struts Apache 2.3.3 (including) 2.3.3 (including)
Struts Apache 2.3.4 (including) 2.3.4 (including)
Struts Apache 2.3.4.1 (including) 2.3.4.1 (including)
Struts Apache 2.3.7 (including) 2.3.7 (including)
Struts Apache 2.3.8 (including) 2.3.8 (including)
Struts Apache 2.3.12 (including) 2.3.12 (including)
Struts Apache 2.3.14 (including) 2.3.14 (including)
Struts Apache 2.3.14.1 (including) 2.3.14.1 (including)
Struts Apache 2.3.14.2 (including) 2.3.14.2 (including)
Struts Apache 2.3.14.3 (including) 2.3.14.3 (including)
Struts Apache 2.3.15 (including) 2.3.15 (including)
Struts Apache 2.3.15.1 (including) 2.3.15.1 (including)
Struts Apache 2.3.15.2 (including) 2.3.15.2 (including)
Struts Apache 2.3.15.3 (including) 2.3.15.3 (including)
Struts Apache 2.3.16 (including) 2.3.16 (including)
Struts Apache 2.3.16.1 (including) 2.3.16.1 (including)
Struts Apache 2.3.16.2 (including) 2.3.16.2 (including)
Struts Apache 2.3.16.3 (including) 2.3.16.3 (including)
Struts Apache 2.3.20 (including) 2.3.20 (including)
Struts Apache 2.3.20.1 (including) 2.3.20.1 (including)
Struts Apache 2.3.20.3 (including) 2.3.20.3 (including)
Struts Apache 2.3.24 (including) 2.3.24 (including)
Struts Apache 2.3.24.1 (including) 2.3.24.1 (including)
Struts Apache 2.3.24.3 (including) 2.3.24.3 (including)
Struts Apache 2.3.28 (including) 2.3.28 (including)
Struts Apache 2.3.28.1 (including) 2.3.28.1 (including)
Struts Apache 2.5 (including) 2.5 (including)
Struts Apache 2.5-beta1 (including) 2.5-beta1 (including)
Struts Apache 2.5-beta2 (including) 2.5-beta2 (including)
Struts Apache 2.5-beta3 (including) 2.5-beta3 (including)
Libstruts1.2-java Ubuntu precise *
Libstruts1.2-java Ubuntu trusty *
Libstruts1.2-java Ubuntu upstream *

References