CVE-2016-4436 PUBLISHED CVSS 7.5 HIGH

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

EPSS 4.77% · 89.4th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
4.77%
89.4th percentile

Affected Products

VendorProductVersions
Mavenorg.apache.struts:struts2-core2.0.0, 2.5-BETA1
n/an/an/a
apachestruts2.0.2, 2.0.3, 2.0.4

Timeline

References

Open in Interactive Console →