Cross-site scripting in Apache Struts - CVE-2016-1182
Published: November 30, -0001 / Updated: December 29, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
IBM Tivoli System Automation Application Manager
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
Jira Software Server
Integration Designer
eDiscovery Manager
Fedora
struts
How to mitigate CVE-2016-1182
Jira Software Server - update to 11.2.1
Jira Software Data Center - update to 11.2.1
Jira Service Management Server - update to 11.2.1
Jira Service Management Data Center - update to 11.2.1
struts - addressed in versions 1.3.10-18.fc23, 1.3.10-18.fc24
eDiscovery Manager - update to 2.2.2.3.8
External References
- http://jvn.jp/en/jp/JVN65044642/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-00009
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Related Security Bulletins
- XSS in Apache Struts
- Multiple vulnerabilities in IBM Tivoli System Automation Application Manager
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in IBM eDiscovery Manager
- Fedora 24 update for struts
- Fedora 23 update for struts
- Jira Software Data Center and Server update for Apache Struts
- Jira Service Management Data Center and Server update for Apache Struts