445
VMScore

CVE-2016-4431

Published: 04/07/2016 Updated: 09/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache Struts 2 2.3.20 up to and including 2.3.28.1 allows remote malicious users to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 2.3.28

apache struts 2.3.20.1

apache struts 2.3.20

apache struts 2.3.24.3

apache struts 2.3.24.1

apache struts 2.3.24

apache struts 2.3.20.3

Vendor Advisories

Apache Struts 2 2320 through 23281 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method ...