9.8
CVSSv3

CVE-2016-4436

Published: 03/10/2016 Updated: 09/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Struts 2 prior to 2.3.29 and 2.5.x prior to 2.5.1 allow malicious users to have unspecified impact via vectors related to improper action name clean up.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 2.3.16.2

apache struts 2.3.16.1

apache struts 2.3.14.1

apache struts 2.3.14

apache struts 2.3.1.2

apache struts 2.3.1.1

apache struts 2.1.8

apache struts 2.1.6

apache struts 2.0.3

apache struts 2.0.4

apache struts 2.3.20.1

apache struts 2.3.20.3

apache struts 2.5

apache struts 2.3.15.2

apache struts 2.3.15

apache struts 2.3.8

apache struts 2.3.4.1

apache struts 2.2.3

apache struts 2.2.1.1

apache struts 2.0.11.2

apache struts 2.0.11.1

apache struts 2.0.0

apache struts 2.0.7

apache struts 2.0.8

apache struts 2.3.24.3

apache struts 2.3.28

apache struts 2.3.16

apache struts 2.3.15.3

apache struts 2.3.12

apache struts 2.3.7

apache struts 2.3.1

apache struts 2.2.3.1

apache struts 2.0.14

apache struts 2.0.12

apache struts 2.0.5

apache struts 2.0.6

apache struts 2.3.24

apache struts 2.3.24.1

apache struts 2.3.20

apache struts 2.3.16.3

apache struts 2.3.15.1

apache struts 2.3.14.3

apache struts 2.3.14.2

apache struts 2.3.3

apache struts 2.3.4

apache struts 2.2.1

apache struts 2.1.8.1

apache struts 2.0.1

apache struts 2.0.2

apache struts 2.0.9

apache struts 2.0.11

apache struts 2.3.28.1

Vendor Advisories

Apache Struts 2 before 2329 and 25x before 251 allow attackers to have unspecified impact via vectors related to improper action name clean up ...