Improper input validation in Apache Struts - CVE-2016-1181

 

Improper input validation in Apache Struts - CVE-2016-1181

Published: June 4, 2020 / Updated: December 29, 2025


Vulnerability identifier: #VU28582
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1181
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in ActionServlet.java when handling multithreaded access to an ActionForm instance. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Apache Struts
IBM Tivoli System Automation Application Manager
Oracle Communications Network Integrity
Jira Service Management Data Center
Jira Service Management Server
Jira Software Data Center
Oracle Communications WebRTC Session Controller
Oracle Retail Order Management System
Oracle Retail Markdown Optimization
Jira Software Server
Oracle Retail Clearance Optimization Engine
Integration Designer
eDiscovery Manager
Fedora
struts
Oracle Communications Converged Application Server

How to mitigate CVE-2016-1181

Install updates from vendor's website.

Apache Struts - update to 2.0.0
Jira Service Management Data Center - update to 11.2.1
Jira Service Management Server - update to 11.2.1
Jira Software Data Center - addressed in versions 11.2.1, 11.3.0
Jira Software Server - addressed in versions 11.2.1, 11.3.0
struts - addressed in versions 1.3.10-18.fc23, 1.3.10-18.fc24
eDiscovery Manager - update to 2.2.2.3.8
Oracle Communications Converged Application Server - update to 7.0.0.1
Oracle Communications WebRTC Session Controller - update to 7.2

External References

Related Security Bulletins