CVE-2016-4461: Input Validation
Published Oct 16, 2017
·Updated
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.
Affected Software
3 affected componentsFixes available
Apache struts>=2.0.0<2.3.29
NetApp OnCommand Balance
maven/org.apache.struts:struts2-core>=2.0.0<2.3.29
2.3.29
Event History
Oct 16, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:05 AM
Data Sourced
via GitHub·01:05 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-4461?
CVE-2016-4461 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2016-4461?
To fix CVE-2016-4461, upgrade Apache Struts to version 2.3.29 or later.
3
What software is affected by CVE-2016-4461?
CVE-2016-4461 affects Apache Struts versions prior to 2.3.29 and NetApp OnCommand Balance.
4
What type of attack does CVE-2016-4461 allow?
CVE-2016-4461 allows remote attackers to execute arbitrary code through a specific tag attribute manipulation.
5
Is there a relationship between CVE-2016-4461 and CVE-2016-0785?
Yes, CVE-2016-4461 exists because of an incomplete fix for CVE-2016-0785.