CVE-2016-0785: Input Validation
Apache Struts 2.x before 2.3.20.3, 2.3.24.3, and 2.3.28 allows remote attackers to execute arbitrary code via a %{} sequence in a tag attribute, aka forced double OGNL evaluation.
Other sources
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0785?
CVE-2016-0785 is classified as critical due to its ability to allow remote code execution.
How do I fix CVE-2016-0785?
To fix CVE-2016-0785, upgrade to Apache Struts version 2.3.20.3, 2.3.24.3, or 2.3.28 or later.
What versions are affected by CVE-2016-0785?
CVE-2016-0785 affects all Apache Struts 2.x versions before 2.3.20.3, 2.3.24.3, and 2.3.28.
What type of vulnerability is CVE-2016-0785?
CVE-2016-0785 is a remote code execution vulnerability due to improper handling of OGNL expressions.
Can CVE-2016-0785 be exploited remotely?
Yes, CVE-2016-0785 can be exploited remotely by attackers through specially crafted requests.