Improper Handling of Parameters in Apache Struts - CVE-2016-3082

 

Improper Handling of Parameters in Apache Struts - CVE-2016-3082

Published: April 17, 2024


Vulnerability identifier: #VU88742
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3082
CWE-ID: CWE-233
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of parameters. A remote unauthenticated attacker can trigger vulnerability and execute arbitrary code via the stylesheet location parameter.


Affected software

Apache Struts
Call Center for Commerce
IBM Sterling Order Management

How to mitigate CVE-2016-3082

Install updates from vendor's website.

Apache Struts - addressed in versions 2.3.20.2, 2.3.24.2, 2.3.28.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1

External References

Related Security Bulletins