7.5
CVSSv2

CVE-2016-4438

Published: 04/07/2016 Updated: 12/08/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The REST plugin in Apache Struts 2 2.3.19 up to and including 2.3.28.1 allows remote malicious users to execute arbitrary code via a crafted expression.

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 2.3.20

apache struts 2.3.20.3

apache struts 2.3.20.1

apache struts 2.3.28

apache struts 2.3.24.3

apache struts 2.3.24.1

apache struts 2.3.24

Vendor Advisories

The REST plugin in Apache Struts 2 2320 through 23281 allows remote attackers to execute arbitrary code via a crafted expression ...