CVE-2016-4436: Critical severity apache struts 2 vulnerability
Published Oct 3, 2016
·Updated
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.
Affected Software
57 affected componentsFixes available
maven/org.apache.struts:struts2-core>=2.5-BETA1<2.5.1
2.5.1
maven/org.apache.struts:struts2-core>=2.0.0<2.3.29
2.3.29
Apache struts=2.0.0
Apache struts=2.0.1
Apache struts=2.0.2
Apache struts=2.0.3
Apache struts=2.0.4
Apache struts=2.0.5
Apache struts=2.0.6
Apache struts=2.0.7
Apache struts=2.0.8
Apache struts=2.0.9
Apache struts=2.0.11
Apache struts=2.0.11.1
Apache struts=2.0.11.2
Apache struts=2.0.12
Apache struts=2.0.14
Apache struts=2.1.6
Apache struts=2.1.8
Apache struts=2.1.8.1
Apache struts=2.2.1
Apache struts=2.2.1.1
Apache struts=2.2.3
Apache struts=2.2.3.1
Apache struts=2.3.1
Apache struts=2.3.1.1
Apache struts=2.3.1.2
Apache struts=2.3.3
Apache struts=2.3.4
Apache struts=2.3.4.1
Apache struts=2.3.7
Apache struts=2.3.8
Apache struts=2.3.12
Apache struts=2.3.14
Apache struts=2.3.14.1
Apache struts=2.3.14.2
Apache struts=2.3.14.3
Apache struts=2.3.15
Apache struts=2.3.15.1
Apache struts=2.3.15.2
Apache struts=2.3.15.3
Apache struts=2.3.16
Apache struts=2.3.16.1
Apache struts=2.3.16.2
Apache struts=2.3.16.3
Apache struts=2.3.20
Apache struts=2.3.20.1
Apache struts=2.3.20.3
Apache struts=2.3.24
Apache struts=2.3.24.1
Apache struts=2.3.24.3
Apache struts=2.3.28
Apache struts=2.3.28.1
Apache struts=2.5
Apache struts=2.5-beta1
Apache struts=2.5-beta2
Apache struts=2.5-beta3
Event History
Oct 3, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 17, 2022
Advisory Published
02:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-4436?
CVE-2016-4436 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2016-4436?
To fix CVE-2016-4436, upgrade Apache Struts to version 2.3.29 or 2.5.1 or later.
3
What versions are affected by CVE-2016-4436?
CVE-2016-4436 affects Apache Struts versions before 2.3.29 and 2.5.x before 2.5.1.
4
What kind of impact can CVE-2016-4436 have?
CVE-2016-4436 can allow attackers to achieve unspecified impact due to improper action name clean up.
5
Is CVE-2016-4436 specific to any installation environments?
CVE-2016-4436 is applicable to any installation of vulnerable versions of Apache Struts in various environments.