CVE-2007-4556: Input Validation
Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4556?
CVE-2007-4556 has a severity rating that indicates it may cause a denial of service due to an infinite loop.
How do I fix CVE-2007-4556?
To mitigate CVE-2007-4556, upgrade OpenSymphony XWork to version 2.0.4 or later, or 1.2.3 or later.
What vulnerabilities does CVE-2007-4556 affect?
CVE-2007-4556 affects OpenSymphony XWork versions before 2.0.4 and 1.2.3.
What conditions enable the vulnerability in CVE-2007-4556?
CVE-2007-4556 is exploitable when the altSyntax feature is enabled in the affected versions of XWork.
Can CVE-2007-4556 be exploited remotely?
Yes, CVE-2007-4556 can be exploited remotely, allowing attackers to cause denial of service on affected systems.