CVE-2016-4433

CVSS v3.0 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.53 % (77th)
0.53% Progress
Affected Products 1
Advisories 1

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2016-07-04 22:59:07
(8 years ago)
Updated Date
2017-08-09 01:29:05
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Struts 2.3.20 cpe:2.3:a:apache:struts:2.3.20
  Apache Struts 2.3.20.1 cpe:2.3:a:apache:struts:2.3.20.1
  Apache Struts 2.3.20.3 cpe:2.3:a:apache:struts:2.3.20.3
  Apache Struts 2.3.24 cpe:2.3:a:apache:struts:2.3.24
  Apache Struts 2.3.24.1 cpe:2.3:a:apache:struts:2.3.24.1
  Apache Struts 2.3.24.3 cpe:2.3:a:apache:struts:2.3.24.3
  Apache Struts 2.3.28 cpe:2.3:a:apache:struts:2.3.28
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...