CVE-2016-3093: Input Validation
Published Jun 7, 2016
·Updated
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.
Affected Software
114 affected componentsFixes available
maven/ognl:ognl<3.0.12
3.0.12
maven/org.apache.struts:struts2-core>=2.0.0<=2.3.24.1
2.3.24.3
All of the following
Ognl Project Ognl<=3.0.11
Any of the following
Apache struts=2.0.0
Apache struts=2.0.1
Apache struts=2.0.2
Apache struts=2.0.3
Apache struts=2.0.4
Apache struts=2.0.5
Apache struts=2.0.6
Apache struts=2.0.7
Apache struts=2.0.8
Apache struts=2.0.9
Apache struts=2.0.10
Apache struts=2.0.11
Apache struts=2.0.11.1
Apache struts=2.0.11.2
Apache struts=2.0.12
Apache struts=2.0.13
Apache struts=2.0.14
Apache struts=2.1.0
Apache struts=2.1.1
Apache struts=2.1.2
Apache struts=2.1.3
Apache struts=2.1.4
Apache struts=2.1.5
Apache struts=2.1.6
Apache struts=2.1.8
Apache struts=2.1.8.1
Apache struts=2.2.1
Apache struts=2.2.1.1
Apache struts=2.2.3
Apache struts=2.2.3.1
Apache struts=2.3.1
Apache struts=2.3.1.1
Apache struts=2.3.1.2
Apache struts=2.3.4
Apache struts=2.3.4.1
Apache struts=2.3.7
Apache struts=2.3.8
Apache struts=2.3.12
Apache struts=2.3.14
Apache struts=2.3.14.1
Apache struts=2.3.14.2
Apache struts=2.3.14.3
Apache struts=2.3.15
Apache struts=2.3.15.1
Apache struts=2.3.15.2
Apache struts=2.3.15.3
Apache struts=2.3.16
Apache struts=2.3.16.1
Apache struts=2.3.16.2
Apache struts=2.3.16.3
Apache struts=2.3.20
Apache struts=2.3.20.1
Apache struts=2.3.20.3
Apache struts=2.3.24
Apache struts=2.3.24.1
Ognl Project Ognl<=3.0.11
Apache struts=2.0.0
Apache struts=2.0.1
Apache struts=2.0.2
Apache struts=2.0.3
Apache struts=2.0.4
Apache struts=2.0.5
Apache struts=2.0.6
Apache struts=2.0.7
Apache struts=2.0.8
Apache struts=2.0.9
Apache struts=2.0.10
Apache struts=2.0.11
Apache struts=2.0.11.1
Apache struts=2.0.11.2
Apache struts=2.0.12
Apache struts=2.0.13
Apache struts=2.0.14
Apache struts=2.1.0
Apache struts=2.1.1
Apache struts=2.1.2
Apache struts=2.1.3
Apache struts=2.1.4
Apache struts=2.1.5
Apache struts=2.1.6
Apache struts=2.1.8
Apache struts=2.1.8.1
Apache struts=2.2.1
Apache struts=2.2.1.1
Apache struts=2.2.3
Apache struts=2.2.3.1
Apache struts=2.3.1
Apache struts=2.3.1.1
Apache struts=2.3.1.2
Apache struts=2.3.4
Apache struts=2.3.4.1
Apache struts=2.3.7
Apache struts=2.3.8
Apache struts=2.3.12
Apache struts=2.3.14
Apache struts=2.3.14.1
Apache struts=2.3.14.2
Apache struts=2.3.14.3
Apache struts=2.3.15
Apache struts=2.3.15.1
Apache struts=2.3.15.2
Apache struts=2.3.15.3
Apache struts=2.3.16
Apache struts=2.3.16.1
Apache struts=2.3.16.2
Apache struts=2.3.16.3
Apache struts=2.3.20
Apache struts=2.3.20.1
Apache struts=2.3.20.3
Apache struts=2.3.24
Apache struts=2.3.24.1
Event History
Jun 7, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-3093?
CVE-2016-3093 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2016-3093?
To fix CVE-2016-3093, upgrade to OGNL version 3.0.12 or later and Struts version 2.3.24.3 or later.
3
What versions are affected by CVE-2016-3093?
CVE-2016-3093 affects Apache Struts versions from 2.0.0 to 2.3.24.1 and OGNL versions up to 3.0.11.
4
What type of vulnerability is CVE-2016-3093?
CVE-2016-3093 is categorized as a denial of service vulnerability.
5
Can CVE-2016-3093 be exploited remotely?
Yes, CVE-2016-3093 can be exploited remotely by attackers to block access to a website.