Improper Handling of Parameters in Apache Struts - CVE-2016-3082
Published: April 17, 2024
Vulnerability identifier: #VU88742
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3082
CWE-ID: CWE-233
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of parameters. A remote unauthenticated attacker can trigger vulnerability and execute arbitrary code via the stylesheet location parameter.
Affected software
Apache Struts
Call Center for Commerce
IBM Sterling Order Management
Call Center for Commerce
IBM Sterling Order Management
How to mitigate CVE-2016-3082
Install updates from vendor's website.
Apache Struts - addressed in versions 2.3.20.2, 2.3.24.2, 2.3.28.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1
Call Center for Commerce - update to 10.0.12
IBM Sterling Order Management - update to 10.0.2403.1