CVE Vulnerabilities

CVE-2016-4436

Published: Oct 03, 2016 | Modified: Aug 09, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

Affected Software

Name Vendor Start Version End Version
Struts Apache 2.0.0 (including) 2.0.0 (including)
Struts Apache 2.0.1 (including) 2.0.1 (including)
Struts Apache 2.0.2 (including) 2.0.2 (including)
Struts Apache 2.0.3 (including) 2.0.3 (including)
Struts Apache 2.0.4 (including) 2.0.4 (including)
Struts Apache 2.0.5 (including) 2.0.5 (including)
Struts Apache 2.0.6 (including) 2.0.6 (including)
Struts Apache 2.0.7 (including) 2.0.7 (including)
Struts Apache 2.0.8 (including) 2.0.8 (including)
Struts Apache 2.0.9 (including) 2.0.9 (including)
Struts Apache 2.0.11 (including) 2.0.11 (including)
Struts Apache 2.0.11.1 (including) 2.0.11.1 (including)
Struts Apache 2.0.11.2 (including) 2.0.11.2 (including)
Struts Apache 2.0.12 (including) 2.0.12 (including)
Struts Apache 2.0.14 (including) 2.0.14 (including)
Struts Apache 2.1.6 (including) 2.1.6 (including)
Struts Apache 2.1.8 (including) 2.1.8 (including)
Struts Apache 2.1.8.1 (including) 2.1.8.1 (including)
Struts Apache 2.2.1 (including) 2.2.1 (including)
Struts Apache 2.2.1.1 (including) 2.2.1.1 (including)
Struts Apache 2.2.3 (including) 2.2.3 (including)
Struts Apache 2.2.3.1 (including) 2.2.3.1 (including)
Struts Apache 2.3.1 (including) 2.3.1 (including)
Struts Apache 2.3.1.1 (including) 2.3.1.1 (including)
Struts Apache 2.3.1.2 (including) 2.3.1.2 (including)
Struts Apache 2.3.3 (including) 2.3.3 (including)
Struts Apache 2.3.4 (including) 2.3.4 (including)
Struts Apache 2.3.4.1 (including) 2.3.4.1 (including)
Struts Apache 2.3.7 (including) 2.3.7 (including)
Struts Apache 2.3.8 (including) 2.3.8 (including)
Struts Apache 2.3.12 (including) 2.3.12 (including)
Struts Apache 2.3.14 (including) 2.3.14 (including)
Struts Apache 2.3.14.1 (including) 2.3.14.1 (including)
Struts Apache 2.3.14.2 (including) 2.3.14.2 (including)
Struts Apache 2.3.14.3 (including) 2.3.14.3 (including)
Struts Apache 2.3.15 (including) 2.3.15 (including)
Struts Apache 2.3.15.1 (including) 2.3.15.1 (including)
Struts Apache 2.3.15.2 (including) 2.3.15.2 (including)
Struts Apache 2.3.15.3 (including) 2.3.15.3 (including)
Struts Apache 2.3.16 (including) 2.3.16 (including)
Struts Apache 2.3.16.1 (including) 2.3.16.1 (including)
Struts Apache 2.3.16.2 (including) 2.3.16.2 (including)
Struts Apache 2.3.16.3 (including) 2.3.16.3 (including)
Struts Apache 2.3.20 (including) 2.3.20 (including)
Struts Apache 2.3.20.1 (including) 2.3.20.1 (including)
Struts Apache 2.3.20.3 (including) 2.3.20.3 (including)
Struts Apache 2.3.24 (including) 2.3.24 (including)
Struts Apache 2.3.24.1 (including) 2.3.24.1 (including)
Struts Apache 2.3.24.3 (including) 2.3.24.3 (including)
Struts Apache 2.3.28 (including) 2.3.28 (including)
Struts Apache 2.3.28.1 (including) 2.3.28.1 (including)
Struts Apache 2.5 (including) 2.5 (including)
Struts Apache 2.5-beta1 (including) 2.5-beta1 (including)
Struts Apache 2.5-beta2 (including) 2.5-beta2 (including)
Struts Apache 2.5-beta3 (including) 2.5-beta3 (including)

References