CVE-2016-1181: High severity oracle banking platform vulnerability
A vulnerability in Apache Struts 1 ActionForm allowing unintended remote operations against components on server memory, such as Servlets and ClassLoader, was found.
Affects Apache Struts versions 1.0 through 1.3.10
External References:
https://jvn.jp/en/jp/JVN03188560/
Other sources
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1181?
CVE-2016-1181 is considered a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2016-1181?
To address CVE-2016-1181, upgrade to a patched version of Apache Struts beyond 1.3.10.
Which versions of Apache Struts are affected by CVE-2016-1181?
CVE-2016-1181 affects Apache Struts versions from 1.0 to 1.3.10.
What type of vulnerability is CVE-2016-1181?
CVE-2016-1181 is a remote code execution vulnerability that allows unintended operations against server components.
Can I safely use Apache Struts version 1.3.10 with CVE-2016-1181?
No, using Apache Struts version 1.3.10 is unsafe due to the known vulnerability CVE-2016-1181.