Stack-based buffer overflow in Apache Struts - CVE-2016-4436
Published: April 17, 2024
Vulnerability identifier: #VU88741
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4436
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists via vectors related to improper action name clean up.. A remote unauthenticated attacker can trigger the vulnerability and execute arbitrary code on the target system.
Affected software
Apache Struts
Call Center for Commerce
IBM Sterling Order Management
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2016-4436
Install updates from vendor's website.
Apache Struts - update to 2.5.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1