Stack-based buffer overflow in Apache Struts - CVE-2016-4436

 

Stack-based buffer overflow in Apache Struts - CVE-2016-4436

Published: April 17, 2024


Vulnerability identifier: #VU88741
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4436
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists via vectors related to improper action name clean up.. A remote unauthenticated attacker can trigger the vulnerability and execute arbitrary code on the target system.


Affected software

Apache Struts
Call Center for Commerce
IBM Sterling Order Management

How to mitigate CVE-2016-4436

Install updates from vendor's website.

Apache Struts - update to 2.5.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1

External References

Related Security Bulletins